Controlling coding agent dependency installs with ToolPolicy and egress allowlists
HowDevelop · x · 2026-10-04
To mitigate supply-chain risk when coding agents autonomously run npm install or pip install:
- Apply a ToolPolicy to the agent's shell tool (e.g. Bash), evaluating command arguments against CEL rules and enforcing them.
- Layer an egress allowlist restricting downloads to an approved internal package mirror or proxy — but the mirror's approval process matters too; allowing a registry doesn't make every package inside it safe.
- Mind the boundary: ArtifactPolicy governs OCI artifacts (agent definitions, MCP servers, skills, policy bundles); npm/PyPI installs fall under ToolPolicy.
- Key pattern: control both the installation action and the source it downloads from.
More from coding & agent
- Fortnox Doc MCP serves 377 API endpoints' docs straight into your AI assistant — modelcontextprotocol · 2026-10-04
- Teams are consolidating into monorepos to make them easier for AI agents to work with — neal_lathia · 2026-10-04
- Using Skills and Memory to audit spreadsheets with traceable findings and saved preferences — FellMentKE · 2026-10-04
- Project-based iteration keeps what landed in AI video, with Codex and Dreamina CLI automating the loop — FellMentKE · 2026-10-04
- Turning research notes into structured, editable proposals and reports with tone control for the audience — FellMentKE · 2026-10-04
- Global Macro Database update brings hundreds of years of macro data to Claude Code and Codex agents — SchoeneggerPhil · 2026-10-04