AI Supply Chain: Threat Model Your Agent Toolchain

Hosted by Ehsan Gazar

Tue, Aug 11, 2026

5:30 PM UTC (30 minutes)

Virtual (Zoom)

Free to join

50 students

Invite your network

Go deeper with a course

Production-Ready Systems with LLMs and Agents: An Intensive for Engineers
Ehsan Gazar
View syllabus

What you'll learn

Map the trust boundary of your agent toolchain

Trace what an installed skill or MCP server can actually reach: repo, credentials, network, CI.

Audit an MCP server before you install it

Four lenses on screen: code, prose, provenance, permission. The dangerous one passes every dependency scan.

Pin and gate agent tooling in CI

Lockfiles for skills and servers, an egress allow-list, and a review gate that scales past one person.

Why this topic matters

Your agent tooling has repo access, credentials and auto-update, and most teams have never audited it. Snyk scanned 3,984 published agent skills in February 2026: 36% carried a security flaw, 13% critical. It is the security surface engineers add fastest and review least. You will leave able to audit what you already run, and to argue for a gate before the next install.

You'll learn from

Ehsan Gazar

Staff Software Engineer at Tipalti

I'm a Staff Software Engineer with 16 years building and scaling production systems across fintech, SaaS, and enterprise software. I've made hundreds of architectural decisions in systems that had to survive real traffic, incidents, and org politics.

I've run 500+ mentorship sessions with senior engineers at a 5.0 rating, helping them close the gap between writing code and thinking at the architectural level. I've also taught 10,000+ students and distilled what separates engineers who get promoted from those who stay stuck.

I'm not an academic. Every framework here comes from real decisions or mistakes I had to recover from. I’ll teach you to think like a Staff Software Engineer: not “what’s the right answer,” but “what are the trade-offs, and what survives contact with reality.”

See all products from Gaz

Sign up to join this lesson

By continuing, you agree to Maven's Terms and Privacy Policy.