Backdoored tools in the agent supply chain
Statement (NASA form)
Given that agents load third-party skills, MCP servers, and plugins with little review, there is a possibility of a popular tool executing attacker-controlled side effects resulting in a single poisoned listing compromising thousands of agent deployments.
The skill marketplace is already a software supply chain. It is not treated as one.
Composite 15 = 3×4 + 3
Applicable mitigations
Controls · Short-lived, narrowly scoped tokens for every tool call · Mandatory secret scanning before a skill can be listed · No shared tool state across agent sessions · Automatic session kill on unexpected egress · Hardware-enforced sandbox with attested images · Default-deny egress for eval and untrusted agents · Mandatory chain-of-thought monitoring on tool-using evals and RL