Supply Chain and MCP Security: Code You Run, Content You Trust

Every tool integration you install is two attack surfaces at once — a process running with your credentials and a writing channel into your model’s context. The attack taxonomy, the disclosed incidents, the review that catches them, and the allowlist process that scales it.

Content current as of 2026-09.

Lessons

  1. Two attack surfaces in one install
  2. The taxonomy: five ways a tool integration turns on you
  3. The record: what has actually happened
  4. The review before you install anything
  5. Org policy: govern tools the way you govern dependencies