Skip to main content

New: Malicious MCP server caught in the wild!

/ KIRIN /

AI coding agents & IDEs: fully secured.

Kirin secures AI coding assistants from prompt injections, rogue behavior, and unsafe execution, so you can code faster and safer.

Critical High Medium by Dashboard Inventory Alerts Shadow AI Agents Activity Policies AI AppSec Users Security Groups Settings Audit Logs Attack Demonstrations Get Started Dashboard Security Overview for Knostic Knostic Organization General Usage A high-level view of organization-wide alerts, coverage, and MCP usage. Top Alerts TitleSeverityScoreUsers AI-instruction file classifi… 97 6 Destructive command 84 3 Prompt injection 82 2 Unapproved MCP server 64 4 Alerts Last 7 days Total: 77 16 10 5 0 Sep 30, 2026 Oct 1, 2026 Oct 2, 2026 Oct 3, 2026 Oct 4, 2026 Oct 5, 2026 Oct 6, 2026 Latest Alerts TitleSeverityDescriptionLast Seen Unpinned MCPserver An MCP server runs from anunpinned, mutable version. October 6, 2026 at04:18:54 UTC Maliciouspackage An agent installed a packageflagged as malware. October 6, 2026 at04:05:53 UTC AI-instructionfile… An instruction file tells the agent toskip code review. October 6, 2026 at03:54:44 UTC Prompt injection A file the agent read tried tooverride its rules. October 6, 2026 at03:40:35 UTC UnapprovedMCP server A developer connected an MCPserver that is not on the allow list. October 6, 2026 at03:32:21 UTC Kirin User Coverage Over Time Total Users 1817 Active Users 1679 Active Users Total Users Last 30 days Policies Coverage 89% Detection Policies Detects active attacks, malicious content, and security threats. These policies are enabled by default to provide immediate protection. 8 enabled out of 9 100% AI Agent Instructions Your rules for how AI coding agents should behave. Kirin audits instruction files (such as CLAUDE.md and .cursorrules) against this catalog and reports… 58 enabled out of 60 100% Allow/Block Lists Manage Allow and Block lists. 2 enabled out of 2 Top MCP Servers by Usage supabase 669 stripe 481 sentry 380 slack 222 atlassian 191

Kirin keeps your agent from misbehaving.

It validates connections and blocks unsafe behavior in real time, inspecting dependencies, extensions, and MCP connections and enforcing policy inline, before the agent acts, so you code fast and safe.

The risks Kirin mitigates

Environment integrity

AI assistants can slip in hallucinated packages. Kirin flags malicious code before it threatens developer environments.

Sensitive data

Prompt injections and oversharing risk exposing secrets. Kirin automatically redacts and guards sensitive data inside your agent.

Catch compromised MCP servers before they compromise your organization

Kirin inspects your MCP connections in real time, flagging misconfigurations, unauthorized access, and malicious activity before they put your organization at risk.

Stop vulnerable or malicious plugins at the source

Kirin continuously monitors IDE extensions and plugins, detecting vulnerabilities and blocking untrusted or risky components before they impact your workflow.

Key capabilities

Real-time dependency scanning

Identify vulnerable or malicious libraries instantly.

Continuous monitoring

Detect and block unsafe MCP servers, extensions, and plugins.

In-IDE guardrails

Surface issues and fixes directly in the developer's environment.

Policy drift detection

Flag insecure configuration changes as they occur.

Centralized audit and visibility

Track security events and actions across teams.

Developer velocity

Enforce secure defaults without slowing developers down.

From one developer to the whole enterprise

For developers

  • Real-time threat scanning for prompt injections and malicious instructions
  • Continuous project scanning across repos
  • Execution monitoring of agent actions

For teams

  • Policy enforcement across all developers
  • Dashboards, alerts, and insights for teams and leaders
  • Open API for your development workflows

For the enterprise

  • Server-level defenses that block risky agent commands
  • Compliance and audit support with detailed logs and reports
  • Extends DLP, DSPM, Purview, and SIEM protections into AI workflows

Works where you code

  • Cursor
  • Claude Code
  • GitHub Copilot
  • Windsurf
  • Codex
  • JetBrains
  • Devin Desktop
  • Gemini CLI

Frequently asked questions

They connect to MCP servers, install plugins, and pull packages, all of which can be exploited if unmonitored.

By validating MCP servers and extensions, scanning dependencies, and blocking unsafe actions in real time inside the agent.

No. Kirin applies policies invisibly, surfacing clear, actionable fixes without interrupting developer workflows.

Central dashboards track configuration drift, blocked actions, and vulnerabilities, turning assistant adoption into a governed process.

Cursor, Claude Code, GitHub Copilot, Windsurf, Codex, JetBrains, Devin Desktop, and Gemini CLI.

Yes, we support Claude Cowork through a plugin.