Originally published on AI Tech Connect.
What you are actually installing When an engineer adds an MCP server to a client configuration, or drops an agent skill into a project directory, the mental model is usually "I added a plugin". That is not what happened. What happened is that a third party now supplies executable code that runs with the developer's own privileges, plus a body of natural-language text that is injected directly into a model's context and read as instruction. Both halves matter, and the second half has no analogue anywhere else in the software supply chain. The framing that became widespread in security writing through 2026 is worth stating plainly: agent security is a supply chain problem first and a prompt injection problem second. Prompt injection gets the attention because it is novel and it demonstrates…
Top comments (0)