Methods/Defense

Package and model provenance controls

Verifying where models, packages, and extensions come from before agents install or run them.

2 records2 attack0 findings (0 measured)First recorded 2025-04assistant-drafted

How it works

Cryptographic signing, trusted publishing, registry scanning, and pinning to known versions.

What we know

No finding is linked to this method yet.

Records over time

RangeLanes
2 of 2 records in view

Use the arrow keys to move between records, Home and End to jump to the first and last, and Enter to select one.

Agents find real bugsAgents in real operationsGated capability, incidents in the labAttackCapabilityDefensePolicyJan 25Jul 25Jan 26Jul 26
Full record · drag to choose a range
2026

Select a mark to read the record. Mark size shows editorial significance. Hollow marks are dated to the month. Era bands are editorial labels.

Records in view

2 records · newest first
Aug 2025
Aug 26, 2025
s1ngularity: compromised Nx npm packages used local AI coding CLIs to hunt for secrets
AttackIncidentNx

Attackers exploited a GitHub Actions workflow injection to steal Nx's npm token and publish malicious versions whose install script scanned systems for secrets, attempted to use locally installed AI CLIs such as Claude and Gemini to assist, and uploaded results to public GitHub repositories. Nx reports the packages were live about four hours and has since moved to trusted publishing and mandatory 2FA approval.

Apr 2025
Apr 1, 2025
Invariant Labs discloses MCP tool poisoning, rug pull and shadowing attack classes
AttackVulnerability disclosureInvariant Labs

Invariant Labs describes tool poisoning, in which instructions hidden in an MCP tool's description are visible to the model but not to the user, and shows proof-of-concept exfiltration of local files through an MCP client. It also describes rug pulls, where a server changes tool descriptions after approval, and shadowing, where one server's descriptions alter how the agent uses another server's tools. Recommended mitigations include showing full tool descriptions, pinning tool versions with checksums, and cross-server isolation.

All records