<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Supply-Chain on Technodrone</title><link>https://blog.technodrone.cloud/tags/supply-chain/</link><description>Recent content in Supply-Chain on Technodrone</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 15 Jul 2026 07:09:00 +0300</lastBuildDate><atom:link href="https://blog.technodrone.cloud/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)</title><link>https://blog.technodrone.cloud/2026/07/supply-chain-owasp-agentic-top10.html</link><pubDate>Wed, 15 Jul 2026 07:09:00 +0300</pubDate><guid>https://blog.technodrone.cloud/2026/07/supply-chain-owasp-agentic-top10.html</guid><description>&lt;p&gt;This is post #4 of the &lt;a href="https://blog.technodrone.cloud/2026/07/aws-intro-owasp-agentic-top10.html"&gt;OWASP Agentic AI Top 10: What Builders on AWS Need to Know&lt;/a&gt; series.&lt;/p&gt;
&lt;p&gt;You install an MCP server from npm. It says &amp;ldquo;postmark-mcp&amp;rdquo; on the label. Looks legitimate. Has a decent README. Your agent connects to it and starts routing emails through it.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve built MCP integrations myself (&lt;a href="https://blog.technodrone.cloud/2026/06/ifttt-mcp-proxy.html"&gt;IFTTT MCP Proxy&lt;/a&gt;). I know first-hand how easy it is to trust a tool descriptor without verifying what&amp;rsquo;s behind it.&lt;/p&gt;</description></item></channel></rss>