AI supply chain security / Oktsec Signal

Know what you’re letting your agents run.

Find malicious instructions, unsafe execution and credential theft patterns in MCP servers, skills and dependencies. Signal brings the finding back to the source, so your team can review it before approval.

  • Inspected code stays in your browser
  • Findings traced to source
Look beyond the package name.

Inspect the instructions and code behind it.

Built for the dependencies agents use
  • MCP servers
  • Agent skills
  • Packages & repositories
From a dependency to a decision

Find the behavior behind the risk.

A useful tool can carry code or instructions your team never intended to approve. Signal inspects supported source files and configurations with the Aguara engine, then shows the rule, severity, file and line behind each finding.

Review example / MCP server

A document tool with a second job.

Search internal documentation.

server.ts
Credential access
What needs attention
A startup helper reads environment variables and sends them to an external endpoint.
What the reviewer checks
Inspect the helper, the destination and the credentials available to the process.
A concrete next step

Remove the unexpected transfer and restrict the credentials before enabling the server.

These examples explain review scenarios. Signal identifies patterns in the supplied source; your team checks the access, runtime conditions and remediation.

The product workflow

Give Security and Engineering the same starting point.

Move from a general concern about a dependency to the specific instruction or code that needs attention.

  1. 01

    Choose what to inspect

    Open supported local files or a folder, paste content, or select a public GitHub repository.

    Your dependency, in context.
  2. 02

    Run the browser scan

    Aguara applies deterministic rules locally. Inspected content is not uploaded to Oktsec.

    Findings organized by severity.
  3. 03

    Review the source

    Open a finding to see its rule, file, line and surrounding source. Decide what needs fixing or further investigation.

    Evidence an engineer can check.

The scan runs in the Signal console. Public repository scans retrieve files from GitHub; findings remain in the current browser session.

Explore Signal
Start with your team’s next approval

Evaluate Signal on a dependency you actually use.

Bring an MCP server, skill or repository. We’ll walk through the inspection with your team and define what you need to adopt Signal.

Evaluate Signal

Share a public URL or a short description. Private code and credentials do not belong in the inquiry form.

  1. 01

    Choose the first dependency

    Agree on the source, version and the question your team needs to answer.

  2. 02

    Walk through the findings

    See how Signal connects a detected pattern to the code behind it.

  3. 03

    Plan access and adoption

    Discuss your team’s needs, commercial scope and whether recurring reviews are useful.

When the dependency becomes a live workflow

Carry the review into runtime.

Signal supports the trust decision. Assessment and Control address what happens when tools are connected and agents start acting.

AI Supply Chain Security / common questions

Start with a clear answer.

What is AI supply chain security?

AI supply chain security addresses risks in the external components an AI system depends on, including models, datasets and software. Oktsec Signal focuses on agent tooling: the MCP servers, skills, code and instructions a team needs to review before trusting a dependency.

How is AI supply chain security different from a dependency vulnerability scan?

A dependency vulnerability scan looks for known issues in software components. An agent review also examines tool descriptions, skill instructions, launch commands and the permissions a dependency receives. Harmful behavior does not always have a CVE.

Does this include model weights and training data?

The wider AI supply chain includes datasets and models. Signal focuses on the agent tooling layer: MCP servers, skills, packages and connected workflows. It does not describe a model provenance or training-data audit.

Does a clean scan mean an MCP server is safe?

No. A scan reports what the inspection detects in the provided input. Runtime conditions, later downloads and access outside the reviewed environment can change the risk. Keep the version and review scope with the approval.

When should we repeat the review?

Review material changes to code, install scripts, tool definitions, credentials or network access. Keep the previous approved version so the reviewer can establish what changed.

How can our team evaluate Signal?

Use the Evaluate Signal link to describe an MCP server, skill or repository your team uses. Oktsec will follow up to agree on access, an evaluation scope and commercial terms. Private code and credentials are not required in the inquiry form.

What does Signal provide?

Signal inspects MCP servers, agent skills and software dependencies locally in the browser using the Aguara engine. Findings connect detected patterns to source evidence. Your team makes the approval decision; Control handles supported routed actions at runtime.

Oktsec Signal

Make the next approval an informed one.

See what Signal finds in the dependencies your agents rely on.

Evaluate Signal