You are correct; however, agents can and do find terrible bugs in some of the most popular software in the world made by some of the most competent engineers on the planet.
I assume what KingOfCoders suggested is to run an agent almost like an antivirus which I guess sounds somewhat interesting but you'd have to re-run it on every update and probably spend many more hours+tokens for such a system to work properly.
But perhaps once inference gets truly cheap repository maintainers should include AI security checks for new software as part of their pipeline? I think that would make sense. Especially for repos that are frequently pwned like npm!