Skip to main content
Table of contents
Chapter 3
PAID
31 min read

Agent Supply-Chain Audit

50-point audit for the upstream surface of an agent stack.

The upstream supply chain of an AI agent is model provenance + MCP server graph + eval-set lineage + secret rotation policy + audit-emit channels. 50 audit points, each with a concrete check and a remediation.

outlined
Full chapter in progress

What this chapter covers

  1. 01Model provenance - vendor lock-in vs multi-vendor routing
  2. 02MCP server graph - first-party vs community, signed vs unsigned
  3. 03Dependency tree - Python, Node, Rust supply-chain risks
  4. 04Secret rotation - capability leases over long-lived keys
  5. 05Eval-set leakage - your golden set is your moat
  6. 06Audit-emit channels - what SOC 2 actually wants
  7. 07The 50-point checklist (printable)