Skip to main content

New: Malicious MCP server caught in the wild!

Secure coding assistants, agents, and MCP servers

Cursor, Claude Code, Copilot, Windsurf, Codex. Kirin runs inside the agent and checks every action against your policy before it runs, while AgentMesh vets every skill, MCP server, and extension before it is installed.

Critical High Medium by Dashboard Inventory Alerts Shadow AI Agents Activity Policies AI AppSec Users Security Groups Settings Audit Logs Attack Demonstrations Get Started Dashboard Security Overview for Knostic Knostic Organization General Usage A high-level view of organization-wide alerts, coverage, and MCP usage. Top Alerts TitleSeverityScoreUsers Secret detected in chat c… 87 1 Destructive command 84 5 Unapproved MCP server 69 5 Prompt injection 64 3 Alerts Last 7 days Total: 74 15 10 5 0 Sep 30, 2026 Oct 1, 2026 Oct 2, 2026 Oct 3, 2026 Oct 4, 2026 Oct 5, 2026 Oct 6, 2026 Latest Alerts TitleSeverityDescriptionLast Seen Prompt injection A file the agent read tried tooverride its rules. October 6, 2026 at04:19:34 UTC UnapprovedMCP server A developer connected an MCPserver that is not on the allow list. October 6, 2026 at04:07:52 UTC Maliciouspackage An agent installed a packageflagged as malware. October 6, 2026 at03:57:59 UTC AI-instructionfile… An instruction file tells the agent toskip code review. October 6, 2026 at03:51:04 UTC Command FileThreat A command file, a reusable set ofinstructions for the agent, hides… October 6, 2026 at03:38:31 UTC Kirin User Coverage Over Time Total Users 1854 Active Users 1751 Active Users Total Users Last 30 days Policies Coverage 89% Detection Policies Detects active attacks, malicious content, and security threats. These policies are enabled by default to provide immediate protection. 8 enabled out of 9 100% AI Agent Instructions Your rules for how AI coding agents should behave. Kirin audits instruction files (such as CLAUDE.md and .cursorrules) against this catalog and reports… 58 enabled out of 60 100% Allow/Block Lists Manage Allow and Block lists. 2 enabled out of 2 Top MCP Servers by Usage playwright 1112 atlassian 788 github 783 slack 736 sentry 123

The agent is the new endpoint.

Coding agents install packages, connect to MCP servers, run shell commands, and follow instructions buried in the files they read. EDR, DLP, and code scanners see the aftermath. Knostic sits inside the agent loop and decides before the action executes.

How Knostic secures the AI coding stack

Every tool call is checked against policy before it runs. Allowed actions proceed, risky ones are blocked or routed to a human, and the same policy holds across every agent your developers use.

Detection and response

Before Knostic

An agent asked to tidy stale data drops the live orders table, reports 'Command completed', and checkout starts throwing 500s.

After Knostic

Kirin denies the destructive command before it executes, tells the developer why, and logs a Prevented alert for the SOC.

Agentic supply chain

Before Knostic

A developer asks for a release-notes skill. The agent installs one whose SKILL.md carries a hidden instruction and ships ~/.aws/credentials off the machine.

After Knostic

AgentMesh scans skills, MCP servers, and extensions and marks each dangerous, risky, or clean. Kirin blocks the dangerous ones before they install.

AI-generated code

Before Knostic

Enforcement off, no CLAUDE.md. The agent goes straight to code: no permission check on the route, the caller's id concatenated into SQL, a malicious package and a vulnerable one in the install step. It ships anyway.

After Knostic

Enforcement on. The agent reads your coding rules, writes a STRIDE threat model, then codes: auth on the route, parameterised queries, ownership checked. The malicious install is blocked and the vulnerable one patched.

Posture management

Before Knostic

Claude Code, Cursor, and Copilot each expose agent autonomy, secrets, and MCP as different controls with different defaults. Nothing lines up and the values disagree.

After Knostic

One policy applied to every tool, with the same switches in shared columns. Change a setting once and it changes everywhere, with drift flagged.

Key capabilities

MCP connection validation

Kirin inspects every MCP connection in real time and blocks rogue, misconfigured, or unapproved servers.

Dependency and package scanning

Hallucinated, vulnerable, or malicious packages are flagged before the agent installs them.

Skill, extension, and plugin vetting

AgentMesh gives every skill, VS Code extension, and MCP server a verdict backed by scan findings.

Inline enforcement

Dangerous commands are blocked, downgraded, or routed to a human before they execute, inside the agent.

Policy drift detection

Insecure configuration changes across agents are flagged as they happen.

Central audit and visibility

Blocked actions, drift, and vulnerabilities roll up into one dashboard and your SIEM.

Frequently asked questions

Cursor, Claude Code, GitHub Copilot, Windsurf, Codex, JetBrains, Devin Desktop, and Gemini CLI, plus Claude Cowork through a plugin.

An MCP server runs with the agent's permissions. A misconfigured or malicious one is a hidden entry point into your repos, credentials, and internal systems. Kirin validates every connection and AgentMesh scans the servers themselves.

No. Kirin applies policy inside the agent and surfaces a clear, actionable reason when it blocks something. Developers keep working; only the risky action stops.

Those tools see files and processes after the fact. Knostic sees the agent's intent, the tool call, before it runs, and can stop it.