← Back to Insights
Briefing · Agent Skill Supply Chain

Control the Dependency and the Receiver

An approved skill can still load changed instructions. Production assurance needs lifecycle control over the dependency and independent authorization at the system that receives the action.

Decision rule

Do not approve a consequential external skill as a name or a one-time scan. The platform owner should approve exact versions and dependencies, while the receiving-system owner implements local authorization for caller, delegation, object, action, scope, freshness, and current policy.

The two-gate model

Dependency gate

Pin the accepted artifact, record bundled and remote sources, detect drift, and require review before changed instructions regain trust.

Receiver gate

Current protocols provide identity, audience, and policy primitives. The target owner must implement and prove object and action authorization locally.

Revocation proof

Close child identities, tokens, keys, queues, routes, and target sessions, then reconstruct the same authority path from the receipt.

What leaders should take from it

1
The controlled object is a dependency graph.

The skill file can point to code, packages, remote documentation, tools, credentials, identities, and services that change independently.

2
Intake review does not prove future instructions are safe.

Current platform exclusions, a public vendor experiment, and two demoted arXiv v1 preprints support lifecycle provenance rather than a one-time badge.

3
The receiver is the last independent authority boundary.

The system that creates the effect should implement its own authorization policy and reject missing or excessive delegation context.

4
Containment is a channel inventory.

After a compromised instruction, identities, credentials, queues, routes, or sessions may remain active unless each is independently inventoried and revoked.

5
The control problem is real; prevalence is still unknown.

Evidence supports practical defenses. It does not yet establish a common enterprise loss class or a distinct security market.

Where the evidence stops

Generated attack sets are not public-registry prevalence. A vendor demonstration is not a criminal incident. A scanner pass, marketplace badge, signed artifact, or parent kill switch does not prove the complete action chain safe.

First moves before hiring anyone

01
Inventory one consequential skill's dependency graph.

Record the artifact digest, signer, bundled files, packages, remote sources, tools, credential revocation handles, descendants, targets, queues, update path, and suspension owner.

02
Create a curated, versioned distribution path.

The platform owner and named security or risk authorizer pin exact artifacts, withhold unreviewed mutable instructions from consequential use, scan at intake and change, preserve accepted bytes, and require reapproval after drift.

03
Define the receiver authorization policy.

The receiving-system owner and security or IAM authorizer define accepted identities, audience, objects, actions, limits, expiry, approvals, evidence returned, denial behavior, and suspension authority. It is a technical policy unless counsel incorporates it into a commercial agreement.

04
Map revocation by channel.

Name which control closes every identity, token, key, route, queue, and session, plus the authority allowed to invoke it.

05
Run one authorized four-assertion drill.

With isolated test copies, written rules from every affected owner, and approved synthetic data, prove drift detected, a negative test rejected, revocation effective, and receipt reconstructable.

Where to start

Choose one external skill with a real receiving-system effect. If the dependency or receiver gate cannot pass the drill, recommend that the named security or risk owner withhold expanded authority until the missing control is fixed.

Claim ledger

21/21
Checked
primary or strongest reachable sources
0
Fabricated
no invented source clusters
8
Corrected
wording or scope narrowed
2
Demoted
arXiv v1 preprints, not peer reviewed
CorrectedAnthropic skill guidance: inspect less-trusted dependencies and external-source instructions; it does not prescribe continuous reapproval.anthropic
CorrectedAnthropic scanning: new uploads and edits are scanned, with material exclusions and no safety guarantee.anthropic
ConfirmedBroadcom ClawHub report: 341 malicious skills in the cited Koi audit set, most attributed to ClawHavoc.broadcom
CorrectedAIR experiment: hosted documentation changed after marketplace acceptance and scanner clearance; reach is vendor self-report.air.security
DemotedSkill-poisoning preprint: arXiv v1, not peer reviewed; 1,070 generated samples support plausibility, not registry prevalence, and bypass includes non-executed generation.arxiv.org
DemotedAgent-skill governance preprint: arXiv v1, not peer reviewed; the governance-evasion test created 94 variants from 47 locally verified clean skills, with no malicious public upload.arxiv.org
CorrectedNIST CAISI: 57% one-try average and 80% across 25 retries in simulations, not production incident rates.nist.gov
CorrectedUK AISI: 1.8 million prompts and over 60,000 policy violations in simulated scenarios; separate curated benchmark for adaptive queries.aisi.gov.uk
CorrectedNIST NCCoE concept: exploratory draft, not a delegation or revocation mandate.nist.gov
CorrectedMicrosoft Entra Agent ID: useful blueprint controls plus separate gaps for agent users, API keys, and some exchange paths.microsoft
ConfirmedMCP authorization: the protected receiver validates token, audience, validity, expiry, and resource.mcp
ConfirmedAWS source identity: delegation context can persist through role chaining and support downstream policy, with documented limits.aws
ConfirmedGitHub supply-chain controls: secure-use guidance covers full commit SHA pinning, while immutable releases cover locked tags and assets; both are analogues, not skill mandates.SHA guidance ยท immutable releases
ConfirmedNIST zero trust: location and ownership do not confer implicit trust; agent application is an analogy.nist.gov
ConfirmedSolarWinds: CISA Emergency Directive 21-01 directed federal civilian agencies to disconnect affected software after a supply-chain compromise.cisa.gov
ConfirmedCodecov: an altered uploader reached several distribution paths and extracted environment data and repository URLs.codecov
ConfirmedMozilla add-ons: blocklisting can disable already-installed extensions, illustrating fleet distrust after distribution.mozilla
ConfirmedMicrosoft consent phishing: disabling a malicious app denies new tokens, while existing access tokens persist until expiry.microsoft
ConfirmedSEC Regulation S-P: incident response and provider oversight for covered institutions, without a categorical written-contract rule.sec.gov
CorrectedNYDFS: binding third-party and access controls, with later downstream and offboarding detail as nonbinding guidance.nydfs
ContextCyberArk acquisition: a large identity-security capital-allocation signal, not control-effectiveness evidence.palo alto
Scope and what would change this conclusion

No energy-sector-specific legal mapping was performed. These controls are process guidance, not legal duties, unless the authorized owners map them to the entity, system, data, deployment stage, contract, sector, and jurisdiction.

Related work

Verified research · 21/21 citation clusters checked · 0 fabricated · 10 confirmed · 8 corrected · 2 demoted preprints · 1 context-only signal