Malicious Model, Artifact, Skill, Plugin, or Extension
A model file, pickle, dataset, agent skill, MCP package, plugin, coding extension, container, or dependency is suspected malicious, trojanized, untrusted, or replaced.
Trigger: A model file, pickle, dataset, agent skill, MCP package, plugin, coding extension, container, or dependency is suspected malicious, trojanized, untrusted, or replaced.
Severity guide: Severity 1 when loaded in production, capable of execution, connected to secrets or source code, or distributed to customers.
First 15 minutes
- Stop distribution and quarantine the component without opening it on an analyst workstation.
- Preserve the original bytes, source URL, hash, signature, registry metadata, and deployment history.
- Identify every build, image, host, agent, repository, and environment that used it.
- Revoke related credentials and network access if execution is suspected.
- Begin supply-chain and endpoint scoping.
First 60 minutes
- Scan and statically analyze in an isolated environment.
- Review serialized code behavior, imports, install scripts, tool descriptions, prompts, egress, and credential access.
- Correlate load or install time with process, file, network, repository, and cloud events.
- Verify source, signer, build provenance, dependency resolution, and registry account history.
- Search for same hash, package name, version, domain, command, or behavior across estate.
- Prepare known-good replacement and rollback.
Evidence checklist
- artifact bytes and cryptographic hashes
- source, registry, version, signer, and license
- SBOM/AIBOM and build provenance
- CI and deployment logs
- runtime process, file, network, and credential events
- agent trajectories and tool calls
- affected models, datasets, hosts, and customers
Containment options
- quarantine and revoke component
- block hash, package, domain, and registry source
- rotate exposed credentials
- isolate affected build agents or hosts
- remove from CI cache and mirrors
- roll back to signed known-good version
Recovery and durable controls
- signed and verified artifacts
- AIBOM and SBOM linkage
- pre-merge and pre-deploy scanning
- isolated analysis pipeline
- pinned versions and trusted registries
- runtime egress and file monitoring
- revocation and customer notification process
Communications
- Supply-chain owner, legal, procurement, and product are mandatory.
- Coordinate with registry or upstream maintainer.
- Use responsible disclosure when another organization is affected.
- Customer statements name versions and proven impact.
Closure criteria
- All affected deployments and caches are remediated.
- Credentials and hosts are scoped.
- Known-good provenance is verified.
- CI gates catch the test artifact.
- External reporting and customer actions are complete.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- MCP Tool Poisoning, Impersonation, or Rug Pull
- Persistent Memory or RAG Poisoning
- Unauthorized Agent Action or Data Exfiltration
- Shadow or Exposed AI Infrastructure
- Confidential or Sovereign AI Boundary Failure
- AI Provider or Model Gateway Third-Party Incident
- AI Coding Agent Repository or CI Compromise
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.