Threat
An agentic system consumes code, containers, libraries, models, prompts, tool servers, schemas, descriptions, resources, connectors, plugins, metadata, and remote services. A compromised or substituted input can change which actions the agent selects, what authority it requests, or what code executes.
Tool descriptions and schemas are runtime supply-chain inputs. They can influence model behavior even when no package is installed.
Verify dependencies and changes
Maintain an inventory with owner, source, exact version or digest, publisher, build provenance, signature or attestation, permissions, network destinations, data access, update channel, and removal plan. Pin immutable revisions where the ecosystem supports them. Verify artifact digest and provenance against trusted builders and source expectations before deployment.
Review prompt, schema, permission, endpoint, and metadata changes as security changes. Test in a restricted environment. Default new tools to no authority. Detect drift between reviewed inventory and runtime discovery.
Failure and residual risk
A signed artifact can be malicious from its legitimate publisher. Provenance can show how an artifact was built without proving that it is safe. A verified server can later change tool metadata. A transitive package or hosted model can change outside the deployment artifact. Typosquatting can select the wrong dependency before verification.
Supply-chain checks reduce unknown change. Runtime policy must still limit the effects of a compromised component.
Pomerium boundary
Pomerium can restrict access to registered MCP and application routes. It does not verify the source, build, prompt, schema, or model provenance of every connected agent component. Operators must inventory servers and restrict route authority. Agent platforms own component verification and runtime isolation.
Evaluation checklist
- Does inventory include code, models, prompts, tools, schemas, metadata, and hosted services?
- Are versions or digests immutable and verified against trusted provenance where available?
- Do prompt, endpoint, schema, and permission changes receive security review?
- Can runtime discovery reveal an unreviewed or changed tool?
- Would a compromised dependency remain inside a tested least-authority boundary?
