Skip to main content

AI/ML / Multi Agent Refarch / Threats / DEV

MCP supply-chain compromise

CCC.MARefArc.TH29

External MCP servers are compromised, receive poisoned updates, are sabotaged by insiders, or have their protocol and transport manipulated through man-in-the-middle or downgrade attacks, or have connections redirected via DNS and infrastructure attacks, injecting malicious data or logic into services agents consume.

Related Capabilities

IDTitleDescription
CCC.MARefArc.CP17Approved MCP server registry and lifecycleCatalog of approved MCP servers with metadata, capabilities, configuration, and usage constraints, ensuring agents connect only to servers meeting organizational, security, and compliance requirements.
CCC.MARefArc.CP19MCP-interaction zero-trust guardrailsEnforces authentication and authorization for every MCP request and governs which agents may use which tools, applying rate limits and validating tool-call parameters.
CCC.MARefArc.CP08Built-in trusted toolsA collection of bundled, trusted tools providing fundamental capabilities: the MCP client bridge to the external MCP layer, a sandboxed shell, workspace I/O, and web search.

Related Controls

IDTitleDescription
CCC.MARefArc.CN13MCP Server Security GovernanceGovern the onboarding, verification, and ongoing monitoring of MCP servers so that only approved, integrity-verified servers are reachable, and supply-chain compromise is detected.
CCC.MARefArc.CN15Agentic System Credential Protection FrameworkPrevent agents from discovering, extracting, or misusing credentials by brokering secrets outside agent-accessible surfaces and constraining tool access to credential stores.

External Mappings

FrameworkIDRemarks
air-vecAIR-SEC-026-01
air-vecAIR-SEC-026-02
air-vecAIR-SEC-026-03
air-vecAIR-SEC-026-04
air-vecAIR-SEC-026-05