Skip to main content
All posts

Research5 min readUpdated September 29, 2026

The LiteLLM breach and the inventory you don't have yet.

Compromised LiteLLM packages were published on March 24, 2026. A current agent and dependency inventory helps teams find where an affected package was used and what needs review.

Engineers investigating dependency inventory during a late-night incident response session.

On March 24, 2026, compromised versions of LiteLLM were published to PyPI. The incident raised a practical question for teams using AI agents: which systems installed the affected packages, and what could those systems reach?

LiteLLM's affected releases were a software supply-chain incident, linked by its maintainers to a compromised security scanner in their build pipeline. An agent may also depend on a model provider, tool registry, credentials service, orchestration runner, and MCP servers. An inventory should show those connections so a team can identify affected paths when a dependency is compromised.

Why static lists do not catch this

After a package compromise, teams need to ask: do we use it, which systems installed it, and which agents depend on those systems? A package list answers only part of that question. The links between package, agent, credentials, and tools matter too.

Agents may be created by individual teams, embedded in workflows, and connected to tools that change over time. A configuration management database or cloud security tool may show the host without showing every agent dependency. Check those records against observed activity and the agents' configured tools.

What "agent type" actually means

In Hikma's data model, every agent is one of four types, and the type determines the rest of the question.

  • API agents — call hosted model providers and orchestrate tool calls programmatically. Dependency surface: the SDK, the orchestration framework (LiteLLM, LangChain, LangGraph, custom), the secrets store.
  • Web-automation agents — drive a browser or a UI surface. Dependency surface: the headless runtime, the selector logic, the credentials it uses to log in.
  • MCP agents — connect to one or more MCP servers exposing tools or data. Dependency surface: each MCP server, the transport (STDIO, HTTP, SSE), and the permission grant on the other end.
  • Skill agents — install and run a packaged skill from a directory or repository. Dependency surface: the skill source, the version, the manifest, the runtime that executes it.

When LiteLLM was the question, the agents that mattered were the API agents that imported it, and the orchestration runners that wrapped it. When the next library is the question — and there will be a next library — the answer will be a different slice of the same inventory. You cannot run the query if you have not built the index.

Record the dependencies before an incident

A statement that a system is secure does not show what it depends on. After an incident, teams need to ask whether the affected component was in an agent's path. A current dependency record makes that question easier to answer.

Where the audit log earns its keep

Inventory is half of the answer. The other half is what the agent did while it was running. A structured log that can be sent to a SIEM and exported for review helps answer the practical questions: did the agent call an affected endpoint, which records did it touch, and which identity did it use?

What I would do this week if I ran a security team

  1. Step 01Produce a single list of every AI agent in production, tagged by type. If the list takes more than a day, the list is already the finding.
  2. Step 02For each agent, write down the three things it depends on that, if compromised, would compromise it. Most agents have more than three; start with three.
  3. Step 03For each dependency, identify who would notify you of a compromise and how that alert reaches the security team.
  4. Step 04Decide which audit log is the source of truth for what each agent did last week. If it is more than one, that is the next project.

None of those four steps requires Hikma. They require a few hours and a willingness to write down what is true today. The reason to do them is not the next library. It is the audit conversation that follows the next library, and the question that will be asked in it: did you know?

The LiteLLM breach made one thing operational. The supply chain for an AI agent is wider than most security teams have drawn on a diagram. The inventory is the first control. Everything above it depends on it being honest.

See how HikmaAI finds risk, enforces protection and produces evidence on a representative production flow.