What happened
On 24 September 2026 (page dated 29 September 2026), the Cloud Security Alliance published an analysis piece rethinking trust in the AI supply chain beyond model weights, covering MCP servers, skills, and plugins. It defines three distinct trust decisions — artifact trust (who published the component, version, changes), instruction trust (what prompts, tool descriptions, retrieved documents or memory can influence the agent), and execution trust (what data/systems the agent can reach and act on) — and argues that connect-time component approval is not a permanent runtime decision. It cites the 2025 postmark-mcp npm supply-chain backdoor, tool-poisoning research, MCP tool-description injection, and a skills study finding 534 critical-severity issues and 76 confirmed malicious payloads across 3,984 public skills (91% also using prompt injection).
Why it matters
CSA is building the industry consensus layer for agentic-control-plane security (parallel to its welcome of NVIDIA's Open Agent Safety Platform). This piece is a recognised-body articulation of the 'AI supply chain now extends into agent behaviour' problem — a gap that the 2026-09 window's agentic security discussion (CIS MCP Benchmark, OWASP LLM Top 10 2026, NIST AI Agent Security RFI lessons) repeatedly hits. It gives practitioners a three-part trust model (artifact / instruction / execution) to frame component review for MCP servers, skills and plugins, which are the fastest-growing and least-curated parts of the AI software supply chain.
Action needed
Treat skills, MCP servers, plugins and agent configuration as security-sensitive logic, not static artifacts: scan full packages (natural-language instructions plus executable payloads), re-validate at runtime rather than only at install time, inventory blast radius per environment (sandbox vs. developer workstation), and follow CSA's three trust decisions when building agent supply-chain controls.