This paper introduces a blockchain‑backed agentic security framework that protects the entire software development lifecycle (SDLC) and the agentic AI components that monitor it. The framework orchestrates a set of specialized security agents covering source integrity, dependency and SBOM analysis, CI configuration auditing, artifact verification, and runtime policy evaluation. Each agent is supported by a large language model (LLM) that interprets artifacts, reasons over tool outputs, and produces structured security reports.
To ensure agent trustworthiness, every agent generates a cryptographically signed attestation recorded on a permissioned blockchain via smart contracts. The on‑chain components include an agent registry, an immutable attestation log, and an enforceable release‑policy module. Communication among agents and with blockchain nodes is secured through a consortium‑operated certificate authority, providing authenticated and tamper‑resistant interactions.
A detailed use‑case and sequence diagram illustrate how a source‑code security agent performs analysis, anchors its attestation on‑chain, and triggers a verifiable allow/block deployment decision. The proposed framework offers decentralized integrity, transparent provenance, continuous security assurance, and a generalizable architecture for integrating agentic AI into modern software supply‑chain security.
Review