Back

The Agent Supply Chain Framework: 4 Actions to Secure Your AI Agent Add-ons

The Agent Supply Chain Framework: 4 Actions to Secure Your AI Agent Add-ons

Plugin4Shell proved it: attackers are already getting into AI agents through the add-ons those agents trust. Most enterprise security programs can't stop it today. This framework gives you four actions and a scorecard to close the gaps before the next attack.

Niv Hoffman
October 5, 2026
Share

Enterprises are rolling out AI agents faster than they can secure what those agents pull in. Add-ons reach every agent through marketplaces and update themselves in the background. Usually nobody keeps a central record, and nobody reviews them again after the first install.

This framework turns findings from Air's research lab into the four actions every enterprise needs in its plan to secure agents. By the end, you can show where your initiative covers the agent supply chain and where it doesn't

What is AI agent supply chain security?

AI agent supply chain security means protecting the add-ons that AI agents install and run, such as plugins, MCP servers and skills. Add-ons come from marketplaces, update themselves in the background, and are rarely reviewed after the first install. Each one is a way in for attackers, and your agents already depend on dozens of them.

Why are AI agent add-ons a security risk today?

Enterprises are rolling out AI agents faster than they can secure what those agents pull in. Most environments already have three gaps:

  • No central record: Teams can't list every add-on their agents use.
  • Silent updates: Add-ons change after install, and nobody approves the change.
  • One-time review: Add-ons get checked once, if at all, and never again.

Plugin4Shell used exactly these gaps. A single malicious add-on can reach your whole agent fleet before anyone notices.

What's inside the Agent Supply Chain Framework?

The framework is built on findings from Air's research lab. It covers:

  1. Skills, MCPs and plugins are only three examples: Learn the seven other add-on types you didn't know you already have in your environment.
  2. The four actions every initiative needs: Learn how to stop malicious plugins that exploit vulnerabilities like Plugin4Shell from reaching your agent fleet.
  3. A scorecard for your 2027 plan: Check each control against your current initiative and take the gaps into planning.

Who is this framework for?

This framework is for the people who plan agent security programs and the teams who run the agents day to day.

  • CISOs and security leaders: Add the agent supply chain to your 2027 plan and budget, with a clear list of controls to track.
  • AI, AppSec and security architecture teams: Check how your agents install, update and remove add-ons today, and close the gaps before the next attack campaign.
Table of Contents

Frequently Asked Questions

What is Plugin4Shell?

Plugin4Shell is a vulnerability that showed attackers can compromise AI agents through trusted add-ons. A malicious plugin can reach an agent through normal install and update channels.

What counts as an AI agent add-on?

Any component an agent installs to gain new abilities. That includes plugins, MCP servers and skills, plus seven other types covered in the framework.

How do I secure MCP servers and agent plugins?

Start with an inventory of every add-on in use. Then control how add-ons are installed and updated, review them on an ongoing basis, and have a way to remove them fast. The framework explains all four actions in detail.

Is my security program protecting my AI agents?

Probably not completely. Most programs weren't built for agent add-ons. Use the scorecard in the framework to see which controls you have and which are missing.