AI Agent Supply Chain Security: MCP Bill of Materials and Cryptographic Provenance
The OpenClaw malicious skills incident (1,184 confirmed malicious skills across ClawHub, ~20% of the ecosystem) has made AI Agent Supply Chain Security a critical production concern in 2026, with MCP server packages now a primary attack vector for tool poisoning and remote code execution. The defense-in-depth approach requires an AI Bill of Materials (AI BOM) for centralized visibility of all MCP servers and third-party agent dependencies, combined with cryptographic signing of agent skills and runtime guardrails that detect poisoned tools or prompts triggering unauthorized tool use. Baseline governance should reference NIST AI RMF and OWASP Top 10 for Agentic Applications, with least-privilege just-in-time credential provisioning replacing broad standing agent access.
Source
↳ Follow the thread