Free Lesson
AI Supply Chain: Threat Model Your Agent Toolchain
30 min
Aug 11, 2026 1:30 PM
Virtual (Zoom)
In this video
What you'll learn
Map the trust boundary of your agent toolchain
Trace what an installed skill or MCP server can actually reach: repo, credentials, network, CI.
Audit an MCP server before you install it
Four lenses on screen: code, prose, provenance, permission. The dangerous one passes every dependency scan.
Pin and gate agent tooling in CI
Lockfiles for skills and servers, an egress allow-list, and a review gate that scales past one person.
Why this topic matters
Your agent tooling has repo access, credentials and auto-update, and most teams have never audited it. Snyk scanned 3,984 published agent skills in February 2026: 36% carried a security flaw, 13% critical. It is the security surface engineers add fastest and review least. You will leave able to audit what you already run, and to argue for a gate before the next install.
