The Toolchain Is the Target: Securing Software Development in the Agentic Era

JFrog finds AI development tools are expanding the software supply chain and creating new attack paths for organizations.

Written By
PD
Paul Davis
Aug 26, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

For most of my career, software supply chain security meant scrutinizing what developers pull in: dependencies, base images, third-party packages. 

That framing is now dangerously incomplete. 

Over the past year, attackers moved upstream, past the packages and into the tools developers use to write code in the first place. 

IDE extensions, AI coding assistants, and Model Context Protocol (MCP) servers are standard developer infrastructure today. 

They hold access to codebases, credentials, and CI/CD pipelines. And most security frameworks were never built to see them.

This is a structural shift, not a hypothetical one. According to JFrog’s 2026 Software Supply Chain Security State of the Union, 41% of organizations now actively use AI and ML libraries, up from 34% a year earlier, and the average organization is managing 47% more of these packages than last year. 

The supply chain didn’t just add an AI category. Increasingly, AI is the supply chain.

Key takeaways

  • Developer tooling is now part of the software supply chain, with IDE extensions, MCP servers, AI models, and agent skills creating new attack paths.
  • Governance is lagging adoption, as only 43% of organizations maintain a policy-enforced set of approved developer tools.
  • AI ecosystems are already being weaponized, with malicious extensions, agent skills, and models appearing across widely used registries.
  • Exploitability matters more than vulnerability volume, with only 12% of 337 high-profile CVEs tested proving highly exploitable in real environments.
  • Visibility must translate into action, requiring security teams to connect provenance, applicability, policy, and audit evidence across the development lifecycle.

The attack surface followed the developers

Consider what happened in the tooling layer alone. The OpenVSX registry — used by AI-native IDEs — grew from roughly 1,000 extensions in 2023 to 3,803 in 2025, a 262% increase. 

That same year, 56 malicious extensions were detected there, including GlassWorm, the first self-propagating worm targeting VS Code extensions. 

GlassWorm hid malicious code inside invisible Unicode characters, harvested developer credentials to spread on its own, and reached approximately 35,800 installations.

The agentic layer fared no better. JFrog Security Research identified more than 20 critical remote code execution vulnerabilities across MCP servers in 2025, including CVE-2025-6514, a CVSS 9.6 flaw in the widely used mcp-remote utility. 

When the team extended scanning to AI agent skill registries in early 2026, it found 969 malicious agent skills carrying critical-impact payloads. 

On the model side, 495 malicious models were detected on public registries like Hugging Face — the same registries from which 53% of organizations pull models for self-hosting.

Advertisement

Every place developers now work — the extension marketplace, the agent skill registry, the model hub — has become a delivery mechanism. 

The perimeter isn’t a network boundary anymore. It’s the entire act of creating, packaging, and operating software.

The governance paradox

Here’s where the data gets uncomfortable. When asked how they govern MCP usage, 97% of organizations say they operate some form of certified list. 

On paper, that looks like maturity. But governance without continuous scanning is a list, not a control.

The broader tooling picture confirms the gap. 

Only 43% of organizations maintain a certified, policy-enforced set of pre-approved developer tools, and 39% use automated controls to block unapproved ones. 

Meanwhile, 18% have either no governance at all or governance in name only — and another 10% rely entirely on developers to self-govern under deadline pressure, pushing the effective ungoverned share toward a quarter of organizations. 

Against a threat landscape that produced GlassWorm and a 9.6-severity MCP vulnerability in a single year, that is the clearest gap in enterprise security today.

Precision is the antidote to noise

None of this calls for more alerts. The research makes the opposite case. 

We built applicability scanners for 337 high-profile CVEs published in 2025 — testing not just whether vulnerable code exists, but whether the conditions to exploit it are actually present in real enterprise environments. 

Only 40 of those CVEs, about 12%, proved highly exploitable in practice. 

Volume-based triage is failing security teams: more CVEs to chase doesn’t mean more actual risk. 

It means more noise, and noise is where real threats hide.

For CISOs, this is the argument to bring to the board. 

The question isn’t how many findings your tools generate — it’s whether you can prove which ones matter in your environment, and act on them before an attacker does.

Advertisement

Visibility without accountability isn’t governance

One more data point should give every security leader pause: 59% of organizations report full production provenance visibility, yet 48% still need a week or more to generate compliance audit proof. 

Those numbers cannot both reflect a healthy program. 

If visibility were real — structured, accessible, audit-ready — proof would take minutes, not weeks. 

For many organizations, “full visibility” means the data exists somewhere, not that anyone can act on it.

This is why I’m skeptical of the reflexive industry response: bolting a new point solution onto each new AI surface. 

An MCP registry here, an extension scanner there, a model-vetting vendor for the piece after that. 

Notably, 38% of organizations now say they rely primarily on the security capabilities of their existing DevOps platform — a recognition that fragmented data islands are themselves a liability. 

Your mission was never to secure one small artifact class at a time. 

It’s to secure the entire AI application, from the first line of AI-assisted code to the agent running in production.

The job of the modern CISO is to help the business move fast and stay safe at the same time — to enable the speed the agentic era demands, not to slow it down. 

That requires a single system of record across everything developers build with and everything AI touches: one place where provenance, applicability, and policy live together. 

The organizations that get there first won’t just be safer. They’ll be faster, too — because they’ll spend their time on the risk that’s real, not the noise that isn’t.

PD

Field CISO at JFrog

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.