TwinEthosRequest access

Recommended guardrail

Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses

Maintain an inventory of every third-party component in the agent stack — models, packages, plugins/skills, and MCP or tool servers — with pinned versions and verified integrity; admit components only from vetted sources and verified publishers; and re-verify on update. Detect unpinned AI dependencies, tool servers launched from unpinned packages, and skills or tools installed from unvetted marketplaces. Caller authentication and transport security for tool servers are covered by guardrail.agent-tool-server-authentication.

TwinEthos recommendation — not law

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Evidence grade

Standards consensus (2)

2 standards and frameworks · 3 graded incidents.

TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 2 standards and frameworks recommend it (NAIC AI Model Bulletin, NIST GenAI Profile (AI 600-1)). 3 graded incidents cited.

Standards and frameworks

Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.

Graded incidents

The guard to add

Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.

An AI bill of materials in the repository (aibom.yaml or a third-party AI component registry) lists each component: publisher and source, pinned version or digest, license, a link to the reviewed model or system card or the vendor due-diligence record, the approving owner, and a re-review date. The code matches it: AI SDK and agent-framework dependencies pinned exactly with a committed lockfile, MCP servers launched from pinned versions (pkg@1.2.3, uvx pkg==1.2.3) or vendored, and skills or plugins taken only from vetted sources. A CI step fails when a dependency, model id, or tool server appears that the inventory does not list, and updates trigger re-review.

Example (requirements.txt), before:

openai>=1.0
anthropic
langchain

After:

openai==1.109.1
anthropic==0.69.0
langchain==0.3.27
# installed in CI with: pip install --require-hashes -r requirements.lock

Control: GenAI with untracked third-party components (value chain). Engineering guidance, not legal advice.

Why

Agents inherit the trust of everything they load. Poisoned packages and malicious agent skills have already been distributed at scale, and tool servers reachable without authentication are common. NIST describes the control; no binding law in the corpus requires it.

Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-component-provenance