
State of the Agentic Development Supply Chain Report
AI agents are no longer just suggesting code—they’re taking actions, connecting to production systems, and operating with growing autonomy. And the supply chain they depend on—MCP servers, skills, integrations—is proliferating well beyond what existing security programs are designed to cover.
Snyk Research scanned nearly 10,000 developer environments to measure the scale of this shift and the risk already embedded in it.
Key findings:
- 50.8% of developers already have MCP server connections running—often installed without review
- 1 in 12 developers with MCP servers have a HIGH or CRITICAL finding today
- 28% of agent skills expose agents to uncontrolled third-party content at runtime
