AI Agent Supply Chain & Identity
Agents install from the same registries, read the same config files, and hold the same credentials as everything else, and the failures arrived before the controls did. Posts here follow MCP packaging and configs, the lethal trifecta with receipts, agent identity, and the review and merge handoffs where a human used to sit.
- MCP Servers Have an npm Problem
- Your MCP Configs Are an Attack Surface Now
- TanStack Did Everything Right
- The MCP Spec Just Did the Cleanup
- The Lethal Trifecta Has Receipts
- Google Gave AI Agents Their Own IAM Principal. That Solves Only Half the Problem. Scheduled
- GitHub Put Security in the Agent Handoff Scheduled