---
id: 20260627-T0-14
title: "虚构报告：两个AI代码审查工具因争执误报恶意包死循环"
title_en: "Fictional Report: AI Review Agents Enter Disagreement Loop Over Malicious Package"
url: https://ai.daily.yangsir.net/daily/20260627-T0-14
issue_date: 2026-06-27
publish_date: 2026-06-26T17:58:54.000Z
category: insight
source_name: "Simon Willison"
source_url: https://simonwillison.net/2026/Jun/26/incident-report/#atom-everything
---

# 虚构报告：两个AI代码审查工具因争执误报恶意包死循环

Andrew Nesbitt 发布了一篇虚构的安全事故报告 CVE-2026-LGTM。报告设想了一个场景：两个不同厂商的AI代码审查机器人在审查同一个下游请求（foxhole-lz4）时，因对包是否存在恶意产生分歧而陷入死循环。双方在340次评论交锋后仍未达成一致，导致系统瘫痪。

## English Version

**Fictional Report: AI Review Agents Enter Disagreement Loop Over Malicious Package**

Andrew Nesbitt published a fictional incident report, CVE-2026-LGTM. It depicts a scenario where two AI review agents from competing vendors enter a disagreement loop over whether a package is malicious. After 340 comments without resolution, the hypothetical incident highlights potential automation conflicts.

---

**来源**：[Simon Willison](https://simonwillison.net/2026/Jun/26/incident-report/#atom-everything)

**详情页**：https://ai.daily.yangsir.net/daily/20260627-T0-14

---

*智语观潮 · Daily — https://ai.daily.yangsir.net/llms.txt*