Respond (RS) · Supply chain
Supply chain at the in agent layer
advisory · Bypassable by language alone
How do I stop the bleeding now?
What this cell does
(no enforcement)
Deliberately empty
This cell has no artifact, and that is the argument rather than a gap. At this layer, for this concern, nothing is enforced. Populating it with an enforcement claim would invert what the framework is saying.
Cell notes
Interventions, Supply chain / In-agent
Empty by design. A compromised package or MCP server cannot be reliably told to stop using itself. Real intervention lives in ../client-side/ (allowlist removal, package quarantine, runtime pin) and ../server-side/ (registry delete, FQDN deny, force redeploy).
Cite this cell:
https://agenticcovenants.com/respond/supply-chain/in-agent/