with acceptance of vibecoded contributions, the trustworthiness of the tool - and things built with it - goes down. it pushes the burden of verification downstream, unless the maintainers can show that they have full understanding of and legal rights to, the contributions.
ken thompson (of unix and c) demonstrated in the 80's how he could add code to a compiler binary that in turn added code to everything built with it, including itself, without any visible traces in source code. researchers at the university of minnesota created deliberate exploits in the linux kernel for years without consent to test out the reliability of the reviewers, and the entire university was banned from contributing as a result.
when running tools with ai contributions, you risk doing both of these things on accident because when prs become hundreds of files big nobody can verify everything, and we've already seen ai inject seemingly nonsense code into projects which can be used as a backdoor.