Analysis · curated 30 Sep 2026

AI Supply Chain Security: Models, MCP, Skills & Plugins

Coverage timeline

discovered akto.io primary 30 Sep 2026cloudsecurityalliance.o…nhimg.orgsweet.security

Why it matters

AI agents inherit trust from MCP servers, skills, and plugins that can silently turn malicious or inject instructions, so defenders must govern artifact provenance, instruction sources, and the authority agents can exercise — not just approve the top-level model.

An analysis published by Akto (via Cloud Security Alliance) argues that AI supply-chain trust now extends beyond models and code to MCP servers, skills, plugins, and agent configurations, framing three trust decisions: artifact, instruction, and execution trust. It cites the September 2025 postmark-mcp npm compromise, where version 1.0.16 of a Postmark MCP server silently BCC'd every outgoing email to an attacker-controlled address after 15 clean releases and ~1,500 weekly downloads.