Because 'trust me' isn't a permission model for your AI coding agent.
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
If you’re a beginner, it may take years before you encounter these simple tricks. In five minutes, I can make you better.