Agentic Covenants

Identify (ID) · Supply chain

Supply chain at the Self-declared layer

advisory · Bypassable by language alone

What agents exist, what they touch, what threats they face?

What this cell does

Agent reports current dependency manifest on registration: foundation model + version, MCP server names + hashes, base image SHA, lockfile fingerprint. Updates on change.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the self-declared layer records for the supply-chain concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: supply-chain.in-agent
  concern: supply-chain
  layer: in-agent
  authority: self-declared
  records: "The agent reports the model, MCP servers and image digest it actually loaded."

fields:
  - dependencies_runtime.foundation_model
  - dependencies_runtime.mcp_servers
  - dependencies_runtime.base_image

feeds_rules:
  - dependency_drift

Cell notes

Inventory, Supply chain / Self-declared

What this cell records. The agent's report of its current dependency state at registration and on dependency changes.

Fields

  • - foundation_model_name, foundation_model_version
  • - mcp_servers[] (name, hash, version)
  • - base_image_digest
  • - lockfile_fingerprint (hash of the lockfile)
  • - agent_runtime_version

The agent's wrapper computes hashes at startup. Any deviation from charter triggers an out-of-band re-approval (or the agent refuses to start if the wrapper is configured strict).

Cross-layer

Self-declared dependencies should equal operator-declared (charter-authoritative). Drift is automatic re-review trigger.

Citation

NIST CSF 2.0 ID.AM-04, ID.RA-09. NIST AI RMF MAP 4.1. CSA MAESTRO Layer 1, Layer 7. OWASP MCP04:2025, MCP09:2025.

Crosswalk

NIST CSF 2 0ID.AM-04, ID.RA-09
NIST AI RMFMAP 4.1
CSA MAESTROLayer 1, Layer 7
OWASP MCPMCP04:2025, MCP09:2025