The most dangerous sentence in an AI-assisted project is not “the code failed.” It is “the code worked, so I gave the tool access to everything.” On July 31, npm restricted what granular access tokens configured to bypass two-factor authentication can do. Those tokens can no longer perform sensitive actions such as creating or deleting …