AI agents autonomously pull in packages, MCP connectors, and tools with no ability to judge whether they're safe, creating supply-chain risk that traditional perimeter defenses like prompt filtering, scanners, or sandboxes can't fully address. The proposed alternative, called 'agent immunization', argues security should be built into what an agent consumes, builds, and ships rather than bolted on from outside: nothing is trusted by default, enforcement happens at the point of action, and every action traces to a scoped identity. Human review of every pull request doesn't scale once agents generate hundreds of changes a day, so trust needs to be embedded in the workflow itself to allow safe autonomy at scale.
Table of contents
The Riskiest Thing an Agent Does Isn’t Writing CodeGuarding From the Outside Feels Like Enough – It Isn’tHuman Review Checkpoints Don’t Scale – Immunity DoesStop Caging Agents – Immunize Them105 Impressions1 Comment