{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-018.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-018",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-018.json",
    "title": "MCP server admission gate",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each MCP server is admitted as a supplier: its provenance is recorded in the AIBOM, its tool definitions are hashed and pinned with an alert on change, its authorisation conformance is checked, it is tested with poisoned descriptors and injected outputs, and it has an owner and a review date.",
    "failureModes": [
      "ASI04: Tools, MCP servers, plugins, prompt templates and models that an agent loads, often at run time, can be malicious or become malicious after they were trusted."
    ],
    "scope": "Agents that use MCP servers, and each server before any allow-list names it.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Admission record per server; definition hashes",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "aibom",
        "title": "AIBOM",
        "url": "https://aigovernanceengineer.com/patterns/aibom"
      }
    ],
    "seeds": [
      {
        "id": "mcp-admission",
        "title": "MCP server admission gate",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART25",
          "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
        },
        {
          "id": "AIGE-OBL-ISO42001-A10",
          "name": "A.10 Third-party and customer relationships",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
        },
        {
          "id": "AIGE-OBL-OWASP-AIBOM",
          "name": "AIBOM",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
        }
      ],
      "iso42001": [
        {
          "id": "A.10.3",
          "title": "Suppliers"
        },
        {
          "id": "A.7.5",
          "title": "Data provenance"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "asi04",
          "externalId": "ASI04",
          "name": "Agentic Supply Chain Vulnerabilities",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
        }
      ],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 20,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "Record the publisher, the source repository and a signed release as provenance; hash tool names, descriptions and schemas at admission, because a changed description is a changed instruction.",
      "Run the tests with poisoned descriptors and injected tool outputs before any allow-list names the server; the vendor due-diligence gate covers who answers when it misbehaves and what notice comes before it changes."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
