Skip to main content

Agentic Supply Chain

Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.

Threat

An agentic system consumes code, containers, libraries, models, prompts, tool servers, schemas, descriptions, resources, connectors, plugins, metadata, and remote services. A compromised or substituted input can change which actions the agent selects, what authority it requests, or what code executes.

Tool descriptions and schemas are runtime supply-chain inputs. They can influence model behavior even when no package is installed.

Verify dependencies and changes

Maintain an inventory with owner, source, exact version or digest, publisher, build provenance, signature or attestation, permissions, network destinations, data access, update channel, and removal plan. Pin immutable revisions where the ecosystem supports them. Verify artifact digest and provenance against trusted builders and source expectations before deployment.

Review prompt, schema, permission, endpoint, and metadata changes as security changes. Test in a restricted environment. Default new tools to no authority. Detect drift between reviewed inventory and runtime discovery.

Failure and residual risk

A signed artifact can be malicious from its legitimate publisher. Provenance can show how an artifact was built without proving that it is safe. A verified server can later change tool metadata. A transitive package or hosted model can change outside the deployment artifact. Typosquatting can select the wrong dependency before verification.

Supply-chain checks reduce unknown change. Runtime policy must still limit the effects of a compromised component.

Pomerium boundary

Pomerium can restrict access to registered MCP and application routes. It does not verify the source, build, prompt, schema, or model provenance of every connected agent component. Operators must inventory servers and restrict route authority. Agent platforms own component verification and runtime isolation.

Evaluation checklist

  • Does inventory include code, models, prompts, tools, schemas, metadata, and hosted services?
  • Are versions or digests immutable and verified against trusted provenance where available?
  • Do prompt, endpoint, schema, and permission changes receive security review?
  • Can runtime discovery reveal an unreviewed or changed tool?
  • Would a compromised dependency remain inside a tested least-authority boundary?

Sources and further reading

Keep learning

Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Authorization and Policy

Policy as Code

Treat access policy as a versioned, reviewed, tested, and observable decision artifact with controlled deployment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo