Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects the installation of Model Context Protocol (MCP) servers or AI agent plugins that exhibit characteristics of supply chain risk, such as unverified or unknown publishers, requests for highly sensitive permissions (filesystem write, credential read, unrestricted network egress), or recent public listing, which aligns with AI model supply chain poisoning techniques (AML.T0104).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000