Uploaded August 2026 | Updated September 2026, 2 weeks ago
Feross Aboukhadijeh, founder and CEO of Socket, explains why AI coding agents pull in 50% more open source dependencies than human developers, and the new attack surface that creates, including models hallucinating package names that attackers then register and wait for agents to install. He breaks down why traditional security scanners that only check for known vulnerabilities miss most real threats, why popularity metrics like GitHub stars and download counts can be faked, and walks through the actual signals Socket looks at instead: what the code accesses, what it reads, and what it does when it runs.
Anne Dwane sits down with Feross to get into practical guardrails for non-technical "vibe coders," why prompt injection hasn't become the dominant attack vector he expected, the mechanics of the massive Axios credential theft, and concrete steps any organization can take right now, like setting a minimum release age on new code.
This is an excerpt from our full conversation with Feross Aboukhadijeh. Watch the full episode here: youtu.be/TMC6S7Vjf1A
00:00 Why coding agents pull in 50% more open source code
02:23 How attackers exploit AI's tendency to hallucinate packages
04:50 Why gameable metrics like stars and downloads can't be trusted
06:52 A framework for guardrails around vibe coding
09:11 Why prompt injection hasn't taken off like expected
11:02 Inside the Axios attack and its 300GB credential haul
13:06 What to do if you're hit by a supply chain attack
15:39 Why security is now a board-level concern
Feross Aboukhadijeh, founder and CEO of Socket, explains why AI coding agents pull in 50% more open source dependencies than human developers, and the new attack surface that creates, including models hallucinating package names that attackers then register and wait for agents to install. He breaks down why traditional security scanners that only check for known vulnerabilities miss most real threats, why popularity metrics like GitHub stars and download counts can be faked, and walks through the actual signals Socket looks at instead: what the code accesses, what it reads, and what it does when it runs.
Anne Dwane sits down with Feross to get into practical guardrails for non-technical "vibe coders," why prompt injection hasn't become the dominant attack vector he expected, the mechanics of the massive Axios credential theft, and concrete steps any organization can take right now, like setting a minimum release age on new code.
This is an excerpt from our full conversation with Feross Aboukhadijeh. Watch the full episode here: youtu.be/TMC6S7Vjf1A
00:00 Why coding agents pull in 50% more open source code
02:23 How attackers exploit AI's tendency to hallucinate packages
04:50 Why gameable metrics like stars and downloads can't be trusted
06:52 A framework for guardrails around vibe coding
09:11 Why prompt injection hasn't taken off like expected
11:02 Inside the Axios attack and its 300GB credential haul
13:06 What to do if you're hit by a supply chain attack
15:39 Why security is now a board-level concern
![Building the Company Behind 1 Million Therapy Visits a Month | Jake Cooper (Grow Therapy)
JakeCooper is co-founder and CEO of Grow Therapy, a technology platform that helps mental health providers launch and scale independent, insurance-accepted practices. Since starting the company in the middle of COVID, Jake and his co-founders have scaled Grow Therapy to around a million patient visits a month across 26,000 providers, surpassing $1 billion in annual revenue while operating profitably since year two.
Ben Casnocha sits down with Jake to trace Grow Therapys founding story, from the friction he and his co-founders saw across patients, providers, and payers to the systems-level model that let them scale where others couldnt. They get into how Jake and his co-founders have divided responsibilities and built trust as the company has grown past 600 employees, his contrarian read on hiring and what most CEOs get wrong about spotting high-agency talent, and the deeply personal reason the mission matters to him. The conversation turns to AI, including where Grow Therapy is finding real leverage in matching and provider coaching tools, and Jakes frank take on whether human therapists still have a role as more people turn to LLMs for support between sessions. He also opens up about why hes deliberately stayed out of the public eye, and why thats starting to change.
[00:00] Cold open
[00:50] Welcome to the Village Global Podcast
[01:40] The origin story of Grow Therapy
[04:00] The business model insight behind Grow Therapy
[06:10] Grow Therapys scale today: $1B+ revenue, 26,000 providers
[06:40] What a college cleaning business taught Jake about entrepreneurship
[08:30] Why the mission is personal to Jake
[10:10] Dividing responsibilities with his co-founders
[12:20] Building trust with his co-founders
[15:40] What Jake believes about hiring that most CEOs dont
[18:20] Communication and alignment across 600+ employees
[19:50] Manager effectiveness and the cannon vs. cannonball problem
[20:50] How Jake interviews for high-agency talent
[25:40] Where AI is actually helping inside Grow Therapy
[28:10] Will therapists still have jobs in 10 years?
[32:30] AI as a copilot for human therapists
[33:40] Entrepreneurs Jake admires
[36:20] Why Jake doesnt have an executive assistant
[38:00] Why Jake has stayed out of the public eye
[40:40] Audience Q&A: Grow Therapys day-zero go-to-market
[42:10] Audience Q&A: how AI has shaped the mission
[45:50] Closing thoughts Building the Company Behind 1 Million Therapy Visits a Month | Jake Cooper (Grow Therapy)](https://i.ytimg.com/vi/n4yQ_f7HJyY/mqdefault.jpg)









