Supply Chain and MCP Security: Code You Run, Content You Trust
Every tool integration you install is two attack surfaces at once — a process running with your credentials and a writing channel into your model’s context. The attack taxonomy, the disclosed incidents, the review that catches them, and the allowlist process that scales it.
Content current as of 2026-09.