HIGHOWASP Agentic Top 10 ASI04
Agentic Supply Chain Vulnerabilities
Agentic supply chain risks emerge when AI agents autonomously select, download, and execute third-party tools, plugins, models, or code packages without adequate verification of their integrity, provenance, or safety. This represents a fundamental shift from traditional supply chain risk because the agent itself makes procurement decisions at runtime rather than a human developer at build time. Evaluate vendors on their capabilities for runtime dependency verification, plugin sandboxing, allowlist enforcement for agent-accessible resources, and provenance validation for dynamically loaded components. This challenge is part of the OWASP Agentic AI Top 10 and is critical for enterprises allowing agents to interact with external tool ecosystems.