Table of contents
Chapter 3
PAID
31 min readAgent Supply-Chain Audit
50-point audit for the upstream surface of an agent stack.
The upstream supply chain of an AI agent is model provenance + MCP server graph + eval-set lineage + secret rotation policy + audit-emit channels. 50 audit points, each with a concrete check and a remediation.
outlined
Full chapter in progressWhat this chapter covers
- 01Model provenance - vendor lock-in vs multi-vendor routing
- 02MCP server graph - first-party vs community, signed vs unsigned
- 03Dependency tree - Python, Node, Rust supply-chain risks
- 04Secret rotation - capability leases over long-lived keys
- 05Eval-set leakage - your golden set is your moat
- 06Audit-emit channels - what SOC 2 actually wants
- 07The 50-point checklist (printable)