Agent Plugins Marketplace
← All plugins

owasp-asi04-agentic-supply-chain

v0.0.3

Verify agent components before loading them, and keep verifying, because runtime tool discovery changes the supply chain after deployment. Use when adding an MCP server, agent framework, plugin, tool registry, or model artifact, and when reviewing what an agent may pull at runtime. Do NOT use for ordinary application dependencies already covered by `verify-dependency-exists`.

Agent Plugins1 Skill

By chock-coreLicense: Apache-2.03 GitHub starsUpdated 2 hours ago

Directory evidence

Runtimes
Agent Plugins
Parsed components
1 skill or MCP entry
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Get the plugin

git clone https://github.com/open-coder-ai/chock-catalog

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is agentic-security/owasp-asi04-agentic-supply-chain/.

This listing currently publishes only the generic Agent Plugins format. Automatic install commands for other clients are not generated yet.

Plugin files

agentic-security/owasp-asi04-agentic-supply-chain/
├── plugin.json
└── skills/owasp-asi04-agentic-supply-chain/SKILL.md

Included Skills1

owasp-asi04-agentic-supply-chainskills/owasp-asi04-agentic-supply-chain/SKILL.md

Verify agent components before loading them, and keep verifying, because runtime tool discovery changes the supply chain after deployment. Use when adding an MCP server, agent framework, plugin, tool registry, or model artifact, and when reviewing what an agent may pull at runtime. Do NOT use for ordinary application dependencies already covered by `verify-dependency-exists`.

Plugin manifests1

agentic-security/owasp-asi04-agentic-supply-chain/plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "owasp-asi04-agentic-supply-chain",
  "version": "0.0.3",
  "description": "Verify agent components before loading them, and keep verifying, because runtime tool discovery changes the supply chain after deployment. Use when adding an MCP server, agent framework, plugin, tool registry, or model artifact, and when reviewing what an agent may pull at runtime. Do NOT use for ordinary application dependencies already covered by `verify-dependency-exists`.",
  "author": {
    "name": "chock-core"
  },
  "repository": "https://github.com/open-coder-ai/chock-catalog",
  "license": "Apache-2.0",
  "keywords": [
    "chock",
    "policy-as-code",
    "rule",
    "advise",
    "asi04"
  ],
  "extensions": {
    "io.github.open-coder-ai": {
      "manifest": "manifest.yaml",
      "artifact": "rule",
      "enforcement": "advise",
      "coverage_without_chock": "advisory"
    }
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[owasp-asi04-agentic-supply-chain on Agent Plugins Marketplace](https://pluginsmp.com/plugins/owasp-asi04-agentic-supply-chain)