State of the Agentic Development Supply Chain Report
AI agents are no longer just suggesting code; they're taking actions, connecting to production systems, and operating with growing autonomy. And the supply chain they depend on; MCP servers, skills, integrations; is proliferating well beyond what existing security programs are designed to cover.
Report Snap Shot
Key findings:
- 50.8% of developers already have MCP server connections running; often installed without review
- 1 in 12 developers with MCP servers have a HIGH or CRITICAL finding today
- 28% of agent skills expose agents to uncontrolled third-party content at runtime