Skip to content
Security

Supply Chain Security

Updated Aug 2026 1 min read
Definition

Supply chain security is the practice of managing risks introduced by third-party vendors, software dependencies, and service providers that an organization relies on. In AI agent contexts, it extends to MCP servers, agent platforms, model providers, and the tools agents connect to.

Why It Matters

Every MCP server an organization connects to is a supply chain dependency. The server's code, its hosting environment, its update cadence, and its maintainer's security practices all affect the organization's risk posture.

MCP server supply chain risks include tool poisoning (malicious tool descriptions that manipulate agent behavior), compromised dependencies (vulnerable libraries in the server's codebase), and abandoned servers (unmaintained code with known vulnerabilities).

NIS2 explicitly requires supply chain security assessments for organizations in covered sectors. Organizations deploying AI agents must evaluate the security posture of every MCP server, agent platform, and model provider in their agent architecture.