Detect (DE) · Supply chain
Supply chain at the In-agent (forensic only) layer
advisory · Bypassable by language alone
If this concern is breached, how do we know?
What this cell does
"Where did this dependency come from" forensically traceable through tool-call log.
Deliberately empty
This cell has no artifact, and that is the argument rather than a gap. At this layer, for this concern, nothing is enforced. Populating it with an enforcement claim would invert what the framework is saying.
Cell notes
Sentinels, Supply chain / In-agent
Forensic only. The tool-call log captured per ../../identity/in-agent/ lets you reconstruct which MCP server, package, or tool was invoked at each step. No additional artifact is needed at this cell.
Citation
NIST CSF 2.0 DE.CM-09.
Crosswalk
| NIST CSF 2 0 | DE.CM-09 |
|---|
Cite this cell:
https://agenticcovenants.com/detect/supply-chain/in-agent/