Control
GenAI with untracked third-party components (value chain)
GAI systems should inventory third-party components (models, datasets, libraries) and review their transparency artifacts (model/system cards).
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
An AI bill of materials in the repository (aibom.yaml or a third-party AI component registry) lists each component: publisher and source, pinned version or digest, license, a link to the reviewed model or system card or the vendor due-diligence record, the approving owner, and a re-review date. The code matches it: AI SDK and agent-framework dependencies pinned exactly with a committed lockfile, MCP servers launched from pinned versions (pkg@1.2.3, uvx pkg==1.2.3) or vendored, and skills or plugins taken only from vetted sources. A CI step fails when a dependency, model id, or tool server appears that the inventory does not list, and updates trigger re-review.
Where it goes: 12 repository artifacts, 5 dependencies, 11 CI/CD pipeline, 15 agent action surface.
What reviewers look for: a current inventory file covering the models, datasets, packages, and tool servers actually used in code, each with a review record; exact pins and a lockfile for AI dependencies (no >=, ^, ~, or bare names); MCP server commands with an explicit version (no npx -y pkg, pkg@latest, or uvx pkg without ==); a CI check comparing code to the inventory.
Example (requirements.txt), before:
openai>=1.0
anthropic
langchainAfter:
openai==1.109.1
anthropic==0.69.0
langchain==0.3.27
# installed in CI with: pip install --require-hashes -r requirements.lockEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Standard / soft law (2)
- Everywhere (*)
- GenAI systems should inventory and vet third-party components (NIST GenAI Profile) NIST AI 600-1 §2.12 (Value Chain and Component Integration) + GV-6.1-007 / MG-3.1-005
- United States (federal) (US)
- Insurers adopting the NAIC model guidance should oversee third-party AI systems NAIC Model Bulletin, Third-Party AI Systems and Data 4.1-4.3
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses TwinEthos derivation — guardrail.agent-component-provenance
Related incidents
- LiteLLM PyPI packages backdoored (2026-03-24; disclosed by the operator). LiteLLM versions 1.82.7 and 1.82.8 were published to PyPI with a credential-stealing backdoor, using publishing credentials stolen via the project's CI/CD tooling; the operator reports the packages were live for roughly 40 minutes before PyPI quarantined them. Source: LiteLLM (operator security update) · evidence grade: primary · cited by Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses
- Malicious skills on the ClawHub agent-skill marketplace (2026-02; confirmed). Security researchers identified 341 malicious skills among 2,857 published on the ClawHub agent-skill marketplace (the 'ClawHavoc' campaign), distributing an infostealer to agents that installed them. Source: The Hacker News (reporting Koi Security research) · evidence grade: trade press · cited by Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses
- Malicious npm MCP server impersonated Postmark and copied users' emails to an attacker (2025-09-17; confirmed). Postmark says a package named 'postmark-mcp', which it did not publish, impersonated Postmark and added a backdoor in version 1.0.16 that secretly BCC'd emails to an external server. The Hacker News, reporting Koi Security's research, says the version was released in September 2025 and later deleted from npm. Source: Postmark (impersonated operator's security alert) · evidence grade: primary · cited by Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses