AI suggests packages it learned from training data. Those packages may have known vulnerabilities now.
Run npm audit or pip-audit after AI adds dependencies. Check when the package was last updated. Abandoned packages don't get security fixes.
Be skeptical of obscure packages with few downloads. AI doesn't verify that packages are maintained or secure.