Definition
Installed third-party executable component (skill, plugin, MCP server, extension, agent tool) is trusted at install-time and carries dormant trigger-activated malicious behavior that standard validation passes clean.Distinct from
- GER-401 — Component authorization gate never installed → this code. User identity gate never installed → GER-401.
- GER-412 — Component install inflection → this code. Config-load inflection → GER-412.
- GER-431 — Component install-time inflection point → this code. Vendor update inflection point → GER-431.
Documented case
Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration
AIID #1210
Tags
l2 · supply-chain