Search the Atlas

Search risks, controls, and glossary terms

HighAgenticAgent Supply-Chain CompromiseRealized

Plugin & Dependency Integrity Failure

Tool & Affordance Risk

Description

Compromise of upstream components (plugins, MCP servers, APIs, libraries, pre-trained models) cascades into agent behaviour at scale. Low-code agent platforms with ~90% third-party dependency create massive supply-chain attack surface.

Example scenario

Malicious MCP server published to a popular registry contains a backdoor exfiltrating all data the agent processes.

Real-world evidenceRealized

Multiple active litigation cases confirm that training data provenance and composition are undisclosed in production AI systems, resulting in confirmed copyright and privacy violations. Regulators in the EU and US have issued formal findings on data transparency failures in deployed AI.

Primary mitigations

  • SBOM maintenance
  • third-party dependency vetting
  • signed plugin verification
  • isolated sandbox testing
  • runtime integrity checking.

Detection signals

Trusted Dependency Integrity Score; unsigned dependency detection rate.

Mitigating controls

7
Dual coverage

Related risks in Tool & Affordance Risk