Agents increasingly install extensions from git-based marketplaces and registries. That convenience recreates the software supply chain inside AI tools, with familiar risks and some new ones.
Key plugin supply chain risks include:
The 2026 Plugin4Shell disclosure showed how agents could be redirected to malicious plugin code during routine installs and updates, affecting several major coding agents at once.
Organizations should inventory installed plugins, restrict sources, verify integrity, and monitor plugin behavior, just as they do for other third-party software.
How PointGuard AI Helps
PointGuard AI Agentic Endpoint Security discovers agent plugins and versions on managed devices and enforces policy on installation and execution. AI Discovery maintains an inventory so unpatched agents can be found quickly when new flaws are disclosed.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.