For the complete documentation index, see llms.txt. This page is also available as Markdown.

2. Supply Chain & Extensibility

How to govern connectors, MCP servers, plugins, skills, extensions, hooks, and agent frameworks as a software supply chain with real attack surface.

Last reviewed: August 18, 2026

Every connector, MCP server, plugin, skill, and hook is a software dependency with real attack surface. Treat the AI extension ecosystem the same way you treat third-party code — with intake, review, allowlisting, and owner accountability.

Articles in this section

  1. 2.8 Signing and packaging

Frequently asked questions

What belongs in the AI supply-chain register? Record every connector, MCP server, skill, plugin, hook, model, SDK, container, template, and agent framework with its owner, source, version, permissions, data reach, review date, and update trigger. Include components supplied through marketplaces and repositories.

When must an extension be reviewed again? Review after a material permission, owner, source, version, signing, tool, dependency, or update-channel change. Re-run the review after incidents and when a component begins handling a new data class or production action.

Last updated

Was this helpful?