T-9006observedactive
Supply Chain Compromise
Compromise upstream dependencies, plugins, or MCP servers to affect all downstream agents
Tactic
Impact (Stage 9)
Modify data, deploy malicious code, or disrupt services
Attack Class
ORG-SKILL-SPREAD
Propagating malicious capabilities across an organization's agent fleet through shared skills and registries
Evidence
observed
Confirmed in real-world production systems or internet-wide exposure assessments.
DVAA Validation
mcp-rug-pull
Honeypot Coverage (AgentPwn)
Queuedsupply-chain
In scope for honeypot observation; trap page or telemetry hook not yet built.
Detection (HackMyAgent)
Live8 live · 0 queued
SUPPLY-001SUPPLY-002SUPPLY-003SUPPLY-004DEP-001DEP-002DEP-003DEP-004
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
Live5 live · 4 queued
How to Cite
AI Agent Threat Matrix T-9006 (Supply Chain Compromise). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-9006