Glossary · term

AI tool supply-chain attacks

A class of attacks aimed not at the prompt itself but at an agent's tool ecosystem: malicious packages impersonating AI brands, slopsquatting (registering names hallucinated by a model), fake installers from ads, compromised IDE extensions, and MCP server manifests that inject instructions into the agent's context.

Safety2026Wave 3 · 2025–26Maturity: 2/5

Maturity rationale

single source, early stage

References

Author: SEC