AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to watch register
15Containment & agentsBelow the top 20

Backdoored tools in the agent supply chain

CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent

Statement (NASA form)

Given that agents load third-party skills, MCP servers, and plugins with little review, there is a possibility of a popular tool executing attacker-controlled side effects resulting in a single poisoned listing compromising thousands of agent deployments.

Likelihood
3Probable
Consequence
4Critical
Urgency
3Priority

The skill marketplace is already a software supply chain. It is not treated as one.

Composite 15 = 3×4 + 3

Applicable mitigations

Related on the map