Your Agent Installed What? Securing the New AI Supply Chain

Agents now install and connect to skills, MCP servers, plugins, tools and other agents. That is a new software supply chain, and very few organizations have decided who gets to approve what goes into it.

We are getting specific. Malicious and compromised MCPs, poisoned tools, excessive permissions, third party dependencies, and how an enterprise actually decides what an agent is allowed to install or trust.

One thing sets the urgency. More compute finds more bugs, with no obvious ceiling. If that holds, this attack surface gets cheap to search very fast.

THE PANEL

We are not putting four people on stage to predict what might happen. The room is built around three perspectives.

Someone who has actually compromised an MCP server or an agent tool environment.

Someone inside an enterprise who has rejected a specific tool on security grounds and can name it.

A builder or researcher who can push back on both.

WHO IS IN THE ROOM

Security researchers and offensive security practitioners. CISOs and enterprise security leaders. Founders and engineers building agent infrastructure. Investors backing security and agent tooling.

Hosted with Pebblebed. Part of SF Tech Week.

This is a curated, approval based gathering. Tell us what you are building, breaking or defending.