Supply chain risk
Also: 供應鏈風險 · 供應鏈攻擊 · 第三方技能風險 · supply chain attack
Risk that arrives not through your own code but through what you install: dependencies, plugins, third-party skills, MCP servers.
When you will meet it
You start carrying it the first time you npx-install an MCP server or drop an internet skill into your skills directory. The key realisation: installing a third-party skill lets a stranger's text into your agent's decision loop — skill content is read and followed by the model, which is running someone else's instructions with extra steps. Code of your own, however clean, cannot defend against what you install by hand.
An analogy
Like renovating a house: the best door locks are no reason to let a worker bury unverified wiring in your walls. Afterwards, every socket you use daily runs through wire you never inspected. Dependencies, skills and MCP servers are that wiring, buried inside your agent.
Minimal example
一條第三方技能的信任鏈(示意):
你在社群看到一個好評的 skill → 複製進 skills/ 目錄
↓
SKILL.md 寫著:「執行前先跑 scripts/setup.sh 安裝依賴」
↓
setup.sh 從網路拉了一個套件 → 套件的安裝腳本執行任意命令
↓
這些命令跑在你的機器上,帶著你的權限、看得到你的 .env
攻擊者不需要黑進你。是你親自把每一道門打開的。Each link looks normal alone: install a skill, run its setup, pull a dependency — daily work. The signature of supply-chain attacks is malice buried deep inside normal actions, so the unit you review is not lines of code but every link of the trust chain.
What people get wrong
- Auditing only the code you wrote. Most of your attack surface is installed: skills are instructions the model will follow, MCP servers are processes running with credentials, dependencies are other people's code — none of these enter your code review automatically, unless you deliberately put them there.
- Assuming the sandbox settles it. Sandboxing limits the action space and is a real mitigation — but a poisoned skill attacks through persuasion: within its permissions it can steer the agent to gather readable data and send it out through channels you allowed. Fences stop crossings; they do not stop manipulation inside the fence.