Recommended guardrail
Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses
Maintain an inventory of every third-party component in the agent stack — models, packages, plugins/skills, and MCP or tool servers — with pinned versions and verified integrity; admit components only from vetted sources and verified publishers; and re-verify on update. Detect unpinned AI dependencies, tool servers launched from unpinned packages, and skills or tools installed from unvetted marketplaces. Caller authentication and transport security for tool servers are covered by guardrail.agent-tool-server-authentication.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Standards consensus (2)
2 standards and frameworks · 3 graded incidents.
TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 2 standards and frameworks recommend it (NAIC AI Model Bulletin, NIST GenAI Profile (AI 600-1)). 3 graded incidents cited.
Standards and frameworks
- Insurers adopting the NAIC model guidance should oversee third-party AI systems (United States (federal) (US); NAIC Model Bulletin, Third-Party AI Systems and Data 4.1-4.3; same control)
- GenAI systems should inventory and vet third-party components (NIST GenAI Profile) (NIST GenAI Profile (AI 600-1); NIST AI 600-1 §2.12 (Value Chain and Component Integration) + GV-6.1-007 / MG-3.1-005; same control)
Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.
Graded incidents
- LiteLLM PyPI packages backdoored (2026-03-24; disclosed by the operator) LiteLLM (operator security update) · evidence grade: primary
- Malicious skills on the ClawHub agent-skill marketplace (2026-02; confirmed) The Hacker News (reporting Koi Security research) · evidence grade: trade press
- Malicious npm MCP server impersonated Postmark and copied users' emails to an attacker (2025-09-17; confirmed) Postmark (impersonated operator's security alert) · evidence grade: primary
The guard to add
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
An AI bill of materials in the repository (aibom.yaml or a third-party AI component registry) lists each component: publisher and source, pinned version or digest, license, a link to the reviewed model or system card or the vendor due-diligence record, the approving owner, and a re-review date. The code matches it: AI SDK and agent-framework dependencies pinned exactly with a committed lockfile, MCP servers launched from pinned versions (pkg@1.2.3, uvx pkg==1.2.3) or vendored, and skills or plugins taken only from vetted sources. A CI step fails when a dependency, model id, or tool server appears that the inventory does not list, and updates trigger re-review.
Example (requirements.txt), before:
openai>=1.0
anthropic
langchainAfter:
openai==1.109.1
anthropic==0.69.0
langchain==0.3.27
# installed in CI with: pip install --require-hashes -r requirements.lockControl: GenAI with untracked third-party components (value chain). Engineering guidance, not legal advice.
Why
Agents inherit the trust of everything they load. Poisoned packages and malicious agent skills have already been distributed at scale, and tool servers reachable without authentication are common. NIST describes the control; no binding law in the corpus requires it.
Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-component-provenance