
Or Weis
MCP Server Supply Chain Is Runtime Supply Chain: Tool Manifests Need Policy and Evidence
MCP risk is not frozen at build time. This article explains how to vet third-party MCP servers, treat manifests as security boundaries, enforce runtime authorization, and preserve incident-grade audit evidence.












