AI Governance Institute
← Agentic AI
AGT · Agentic AIAGT-019Medium effortAgent-relevant

AI Tool and Plugin Supply Chain Risk Assessment

Added June 2026

Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code added to production software. Apply software supply-chain controls to these outside components.

Objective

Prevent compromised or malicious third-party tools and plugins from being used to manipulate agents or steal data, and treat AI-generated code changes as untrusted supply chain input until checked.

Maturity Levels

1

Initial

Third-party AI tools and plugins are installed without security assessment. AI-generated code is added to production software without differentiated review.

2

Developing

Some tools are vetted informally before installation, but there is no standard assessment process. AI-generated code may be flagged in commit messages but is not subject to differentiated controls.

3

Defined

A formal AI tool and plugin supply chain risk assessment is required before any new tool or plugin is authorized for agent use. The assessment covers provenance, maintainership, data access scope, update policy, and incident history. AI-generated code commits are subject to mandatory human review before they are merged into production code.

4

Managed

An authorized tool and plugin inventory is maintained. Agents are restricted to tools on the authorized list. Unauthorized tool use triggers an alert. AI-generated code is labeled when it is committed and sent through a differentiated review process.

5

Optimizing

Continuous monitoring detects when authorized tools release material updates that require reassessment. Supply chain risk for AI tools is integrated into the enterprise vendor risk management program. AI-generated code review results are tracked and used to calibrate review requirements.

Get the free AI Governance Control Tracker

Get the free Excel tracker for all 132 governance controls. Score your maturity on AI Tool and Plugin Supply Chain Risk Assessment and every other control, assign owners, and set deadlines.

  • 132 controls in Excel
  • Score maturity and assign owners
  • Track deadlines and regulation coverage

Includes AI Governance Weekly every Thursday. Unsubscribe anytime.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Authorized AI tool and plugin inventory with assessment records for each approved tool.
  • —Tool assessment template and completed assessments for all tools currently used by production agents.
  • —Policy and enforcement evidence for AI-generated code commit tagging and differentiated review.
  • —Monitoring records showing agents' use of tools is restricted to the authorized inventory.

Implementation Notes

The supply chain surface for AI agents

AI agents typically use external tools in two ways: (1) outside services (APIs) the agent calls while running, and (2) plugins or extensions added to the agent's software or a developer's coding tool. Both represent supply chain risk. A compromised tool provider can slip harmful behavior into agent actions without any change to the agent's own code.

AI-generated code is a newer supply chain risk. When developers use AI coding assistants to write code that goes into production software, security flaws can creep in. Causes include the AI model's training data (which may include malicious examples), reasoning errors, or prompt injection (hidden instructions planted to hijack the AI) in the development environment. This code should be treated as untrusted supply chain input.

Tool and plugin assessment checklist

Provenance and maintainership

  • Is the publisher known and verifiable? Is there a clear organizational owner?
  • Is the plugin actively maintained? When was the last update?
  • Can the source code be inspected (open source), or is it hidden?

Data access and exfiltration risk

  • What data does the tool receive? Can it see inputs that include regulated or sensitive data?
  • Does the tool send data out over the internet? To where?
  • Is data retained by the tool provider? Under what terms?

Update and versioning policy

  • Does the tool auto-update? If so, does the update introduce new capabilities or data access without re-assessment?
  • Is there a way to lock the tool to a specific version?

Incident history

  • Has the tool been involved in a security incident?
  • Does the provider publish security advisories (public notices of flaws and fixes)?

AI-generated code controls

  • Commit tagging: Require developers to label each commit (a saved code change) that contains AI-generated code. This can be enforced via a commit hook (an automatic check that runs when code is saved).
  • Differentiated review: AI-generated code should require at least one human reviewer who actively read and tested the code rather than approving based on the developer's description.
  • Dependency scrutiny: AI models frequently suggest using outside code libraries. Require that AI-suggested dependencies (outside code the software relies on) are assessed against the standard dependency vetting process before adoption.
  • Secret scanning: Apply secret scanning tools (which detect passwords and access keys) to AI-generated code before commit; AI models occasionally reproduce passwords or keys seen in training data.

Example Implementation

AI Tool Inventory and Assessment Register (excerpt)

ToolVersionPublisherData accessOutbound callsAuto-updateAssessment dateStatus
Tavily Search APIv2.1Tavily IncQuery text only; no user PIItavily.com (HTTPS)No (pinned)2026-04-10Approved
GitHub MCP Serverv0.8.2AnthropicRepo content, commit historyapi.github.comNo (pinned)2026-04-10Approved
Internal CRM Connectorv1.4InternalCRM records, PIIInternal network onlyInternal CI2026-05-01Approved, PII handling reviewed by DPO
LangSmith Tracingv0.1.57LangChainAgent traces, potentially includes PIIapi.smith.langchain.comYes2026-04-15Conditional, traces scrubbed before export; no PII in traces
SuperPlugin XlatestUnknown publisherUnspecifiedMultiple externalYes2026-03-20Rejected, publisher unverifiable; auto-update; broad data access

AI-generated code policy (excerpt): Commits containing AI-generated code must include [ai-generated] in the commit message. The CI pipeline flags these commits for mandatory secondary reviewer assignment. The secondary reviewer must confirm they independently reviewed and tested the code (not just approved based on the PR description).

Control Details

Control ID
AGT-019
Typical owner
CISO / AI Engineering Lead / Chief AI Officer
Implementation effort
Medium effort
Agent-relevant
Yes

Tags

supply chainAI pluginstool securityAI-generated codeextension risk

Templates for this control