# What is really inside the AI tools you blindly install Page: https://stenobird.com/podcast/no-compromises-1309932/what-is-really-inside-the-ai-tools-you-blindly-install Text version: https://stenobird.com/podcast/no-compromises-1309932/what-is-really-inside-the-ai-tools-you-blindly-install.md Podcast: [No Compromises](https://stenobird.com/podcast/no-compromises-1309932) Published: 2026-06-20T05:00:00+00:00 Episode link: https://share.transistor.fm/s/e1dfffa5 Audio file: https://media.transistor.fm/e1dfffa5/f7b1550a.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/no-compromises-1309932/episodes/what-is-really-inside-the-ai-tools-you-blindly-install Duration seconds: 832 ## Resource When you install a package, you probably skip the source code. But what about the AI skills and CLAUDE.md files you are feeding directly into your agent? In the latest episode of the No Compromises podcast, we discuss whether developers are reading the AI skills they install and why it actually matters. We make the case that unread skills are riskier than unread packages because they quietly shape how your agent thinks and can introduce security vulnerabilities or opinions you would never have agreed to if you had just taken 10 minutes to read them. We also look at the flip side, where reading those skills can make you a better developer, expose you to approaches you did not know existed, and help you guide your agents more intentionally across every project. (00:00) - Do developers actually read package source code (02:19) - Why AI skills are riskier than packages (05:07) - Security risks hiding in unread skill files (09:30) - Reading skills as a learning opportunity (11:49) - Silly bit Want a second set of eyes on the tools and packages your team is trusting? Find out how our code review service can help ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/no-compromises-1309932/episodes/what-is-really-inside-the-ai-tools-you-blindly-install/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/no-compromises-1309932/what-is-really-inside-the-ai-tools-you-blindly-install.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.