Microsoft could sabotage Amazon's AI model by returning poisoned code to accounts registered with @amazon.com email addresses.
(barring a SHA-1 collision, of course)
EDIT: i suppose another approach could be to invent poisoned repos out of whole cloth and only show them to Amazon, but I susepct that'd be even easier to detect.