MITRE ATLAS Mapped 2026 Top AI Agent Security Detection – Publish Poisoned AI Agent Tool (AML.T0104)

Detects the installation of Model Context Protocol (MCP) servers or AI agent plugins that exhibit characteristics of supply chain risk, such as unverified or unknown publishers, requests for highly sensitive permissions (filesystem write, credential read, unrestricted network egress), or recent public listing, which aligns with AI model supply chain poisoning techniques (AML.T0104).