Home › Use Cases › Supply chain

The dependency was the intrusion.

Your agent installs a package. The package was clean when your scanner last saw it. Now it carries a token, calls an MCP server, and acts with credentials you granted on purpose — so nothing here looks like an exploit, because it is not one. This is the runtime half of supply chain risk: what an agent pulls, calls and executes while it runs. Not a manifest audit, and not a replacement for one.

The package was clean when the scanner last saw it. An agent pulls it mid-task and its first call runs with credentials the agent was legitimately granted — so nothing here looks like an exploit, because nothing about it is one. Salience Cyber reads what that call actually does rather than what the manifest declared, and neutralizes it at the point of interaction. Reaching a credential and writing a persistence hook never happen. This is the runtime half of supply chain risk; it is not a manifest audit and not a replacement for one.
See

The dependency surface at runtime

Which packages, tokens, and MCP servers your agents actually reach when they run — across the browser plane and the system plane. Not what a manifest declares, but the calls that happen, and every artifact an AI session creates recorded at birth.

Comprehend

A poisoned dependency behaves differently

The CognitionAI Engine reads what a tool call or a freshly installed package actually does, and what the agent does next — including agent-to-agent and tool-call exchange, the direction a gateway sitting in front of a model never inspects.

Neutralize

Before the agent acts on it

The malicious tool call, or the compromised package's first action, neutralized at the point of interaction — before it reaches a credential, writes a hook, or opens a connection.

Evidence · Salience Cyber Threat Ledger72of 247 documented incidents carry the Supply chain tag#2largest tag in the ledger, behind agentic exploitation46of those 72 are confirmed intrusions, not disclosures236source citations behind themIt rarely arrives alone: of those 72 entries, 27 also carry AI-generated malware, 15 prompt injection, and 13 agentic exploitation. A compromised dependency is usually the delivery mechanism for one of the other classes — which is why reading the agent's behaviour after the install matters more than cataloguing the install itself.Search the ledger →
Fig. 1
In the console
AI File Activity table listing files by direction to and from AI, with kind, size, the AI tool involved, the user, and a flag on sensitive financial documents.

Every File an AI Touched, in One Timeline

Direction, file, kind, AI session, and user — files a person sent to an AI, and files the AI created. Credential files and AI-born binaries that have run are flagged. Metadata only.

See the full product tour
Fig. 2
In the console
AI-sourced artifact panel showing the provenance chain from ChatGPT through the session to the file it created, with path, hash, size and birth timestamp.

Recorded at Birth

The provenance chain for one AI-created artifact: which tool, which session, which file, and its hash and birth time. It has not executed. If it ever runs and reaches out, the egress is already pinned to the session that wrote it.

See the full product tour