AI Integration · BraivIQ AI Engineering Playbook
MCP Tool And Skill Supply-Chain Security: Scoped Sessions, Signed Archives And Digest Verification In Code
Agents no longer carry all their capabilities with them. They connect to MCP servers that expose tools, and they load skill archives that package instructions, scripts and resources - and in doing so they have acquired a software supply chain with exactly the attack surface of a package registry, with one difference: a compromised package runs code on a developer's machine, while a compromised tool or skill directs an agent that can act on your systems. Microsoft's Agent Framework 1.19.0 for Python shows where the industry is heading: MCP sessions scoped per invocation, requests authenticated to the correct identity and origin, skill archives restricted to a known format, and archive digests verified before anything loads. This playbook is a code-side guide to securing the agent supply chain: treating every MCP server and skill as untrusted until verified, pinning and verifying digests of skill archives, signing and verifying tool definitions, scoping sessions and credentials per invocation rather than per process, allow-listing servers and tools with least-privilege scopes, detecting tool-description drift - because a tool whose description changes is a prompt-injection vector - and auditing which server served which tool call, with a registry of approved servers and skills as the control point.
· 13 min read · By BraivIQ Engineering
A supply chain - MCP servers and skill archives are dependencies with the attack surface of a package registry - and the power to act · Per invocation - Agent Framework 1.19.0 scopes MCP sessions per call and authenticates requests to the correct identity and origin · Digest-verified - Skill archives restricted to a known format and verified against a digest before anything loads · Descriptions are prompts - A tool whose description changes after approval is a prompt-injection vector - detect drift
Two years ago an agent's capabilities were whatever its developers wrote into it. In 2026 an agent reaches outward for them: it connects to Model Context Protocol servers that expose tools, data and actions, and it loads skill archives that package instructions, scripts and resources for a job - which is exactly how it should work, and which means every agent now has a software supply chain. That chain has the attack surface the package-registry world spent a decade learning to defend: a malicious or compromised server, a tampered archive, a dependency that quietly changes after it was approved, a name that looks like the one you meant. It also has a difference that raises the stakes. A compromised npm package runs code on a developer's machine. A compromised tool or skill directs an agent that holds credentials and can act on your systems, and it does so through the agent's own reasoning, where a changed description is as effective as changed code. The industry has started to respond with concrete engineering. Microsoft's Agent Framework 1.19.0 for Python now scopes MCP sessions per invocation, authenticates requests to the correct identity and origin, restricts skill archives to ZIP files, and verifies archive digests before loading - tightening, in the release notes' own framing, how agents call external tools and skills. As an AI Agency Developer London that builds agents on third-party servers and community skills, we think the agent supply chain is the least-defended layer in most deployments, and this playbook is how to secure it in code.
Verify Before Load: Digests, Signatures, And Formats
The first discipline is the one package managers learned long ago: nothing loads until it is verified against what was approved. For skill archives that means three controls Agent Framework 1.19 now exemplifies. Restrict the format: accept only a known archive type with a known structure, so a parser is not handed arbitrary content and a path inside the archive cannot escape into the filesystem. Pin a digest: when a skill is approved, record a cryptographic hash of the exact archive, and refuse to load any archive whose hash does not match - which defeats tampering in transit, substitution at the source and silent updates alike. Verify a signature where the publisher provides one, so that provenance - who built this skill - is established, not assumed. For MCP tool definitions the same logic applies to a different artefact: when a server is approved, snapshot the full set of tool definitions it exposes - names, descriptions, input schemas - and record a digest of that snapshot, so that at connection time the live definitions can be compared to the approved ones and any difference treated as a security event. Together these make the approved state of every external capability explicit and checkable, and they move the question from 'do we trust this server or skill?' - which is unanswerable at runtime - to 'is this exactly the server or skill we reviewed?' - which is a hash comparison. A registry of approved servers and skills, holding their digests, signatures and reviewed definitions, is the natural control point, and an agent platform that loads from anywhere else has no supply-chain security at all.
- Restrict archive formats - accept only a known type and structure. Guard against path traversal inside archives.
- Pin and verify digests - record the hash of every approved skill archive and refuse anything that does not match.
- Verify signatures where available - establish provenance rather than assume it.
- Snapshot and digest tool definitions - names, descriptions and schemas of every approved MCP server, compared at connection time.
- Load only from the registry - a central store of approved servers and skills with their digests is the control point.
Scope Everything Per Invocation
The second discipline is the one Agent Framework 1.19 made explicit for MCP: sessions, credentials and identity are scoped to a single invocation rather than shared across the life of a process. A long-lived MCP session with a long-lived credential is a standing channel - if a server is compromised or a tool is poisoned mid-session, everything the session can reach is exposed for as long as it lives, and nothing ties a given tool call to the specific task and user that justified it. Scoping per invocation means a session is opened for a call, with a credential issued for that call, carrying the identity of the agent and the delegated authority of the user for that task, and closed when the call completes. It means every request to the server is authenticated to the correct identity and origin, so a server cannot be reached by a caller it was not approved for and a response cannot come from a server other than the one requested, and it means the blast radius of any compromise is one call's worth of scope. This composes with least privilege at the tool level: an agent is allow-listed to specific servers and, within a server, to specific tools, with scopes no broader than the task requires, so that a server exposing twenty tools lends an agent the two it needs. It also composes with isolation: tools that execute code or reach the network should run in a sandbox whose egress and filesystem access are constrained, so that even a verified tool cannot do more than it was approved to do. Per-invocation scoping is more work than a shared session - it is also exactly the difference between an agent platform that contains a compromised dependency and one that is fully owned by it.
Detect Drift, Audit Everything, And Operate The Registry
The third discipline is operational, because a supply chain is secured continuously or not at all. Drift detection is the heart of it: at every connection, the live tool definitions a server exposes are compared with the approved snapshot, and a change in a name, a schema or - above all - a description is flagged, blocks the changed tool from being used, and triggers re-review, because a description that changed after approval is the signature of a poisoned tool. The same applies to skills: a digest mismatch is not an update to accept but an alert to investigate. Audit closes the loop: every tool call is logged with the server that served it, the digest of the definitions in force, the agent identity, the delegated user, the task and the arguments, so that an incident can be traced to the exact server and definition version involved, and so that a server later found to be compromised can be mapped to every call it influenced. The registry is where these disciplines live as a product: the catalogue of approved servers and skills with their digests, signatures, reviewed definitions and allowed scopes. A review gate through which a new server or skill must pass - who built it, what it exposes, what it needs access to, what it would do if malicious - before any agent may use it. A deprecation path so that superseded or revoked capabilities are removed from every agent that used them, and telemetry showing which capabilities are actually load-bearing. A registry operated this way turns the agent supply chain from an unmanaged risk into the same governed dependency management a mature engineering organisation already applies to its code - with the extra rigour that these dependencies can act.
The Bottom Line
Agents that reach outward for capabilities - MCP servers for tools, skill archives for packaged know-how - have a software supply chain with a package registry's attack surface and a higher ceiling of harm, because a poisoned tool or skill directs an agent that can act, and because a changed description is as effective an attack as changed code. Securing it is engineering the industry already knows, applied with extra rigour, and Microsoft's Agent Framework 1.19.0 shows the direction: restrict archive formats, pin and verify digests, verify signatures, snapshot and digest every approved server's tool definitions, and load only from a registry of approved capabilities. Scope MCP sessions, credentials and identity to each invocation and authenticate every request to the correct identity and origin, with least-privilege allow-lists of servers and tools and sandboxed execution. Detect drift at every connection and treat a changed description or mismatched digest as an incident, not an update, and audit every tool call with the server and definition version that served it. The registry - catalogue, review gate, deprecation path, telemetry - is where these disciplines become an operated control rather than a one-off check. Done this way, the agent supply chain is governed dependency management for dependencies that can act. Left alone, it is the easiest way into every system your agents can reach. Building agents on a verified, scoped, audited supply chain is exactly the integration work we do.
References & Further Reading
- AI Agents Directory - AI agents news brief, October 1 2026 (Microsoft Agent Framework 1.19.0: scoped MCP sessions, authenticated requests, ZIP-only skill archives, digest verification): https://aiagentsdirectory.com/news/ai-agents-news-brief-october-1-2026
- Model Context Protocol - specification: security and authorization: https://modelcontextprotocol.io/specification
- OWASP - Top 10 for LLM applications (supply chain and prompt injection): https://owasp.org/www-project-top-10-for-large-language-model-applications/
- SLSA - supply-chain levels for software artifacts (provenance and verification framework): https://slsa.dev/
- ComposioHQ - awesome-claude-skills (the community skill catalogues that make a registry necessary): https://github.com/ComposioHQ/awesome-claude-skills