Skip to main content

New: Malicious MCP server caught in the wild!

Adopt AI agents at the speed of the market, inside the rules

Trading, risk, and engineering teams run coding assistants and agents on systems that move money and hold client data. Knostic enforces your policy inside each agent and keeps the evidence regulators expect.

Critical High Medium by Dashboard Inventory Alerts Shadow AI Agents Activity Policies AI AppSec Users Security Groups Settings Audit Logs Attack Demonstrations Get Started Dashboard Security Overview for Knostic Knostic Organization General Usage A high-level view of organization-wide alerts, coverage, and MCP usage. Top Alerts TitleSeverityScoreUsers MCP server tool descripti… 100 1 AI-instruction file classifi… 99 1 Unapproved MCP server 63 5 Destructive command 63 7 Alerts Last 7 days Total: 55 11 8 4 0 Sep 30, 2026 Oct 1, 2026 Oct 2, 2026 Oct 3, 2026 Oct 4, 2026 Oct 5, 2026 Oct 6, 2026 Latest Alerts TitleSeverityDescriptionLast Seen Prompt injection A file the agent read tried tooverride its rules. October 6, 2026 at04:20:53 UTC Shadow AIextension An unsanctioned AI extension wasinstalled in VS Code. October 6, 2026 at04:16:51 UTC Secret detectedin chat content An API key was pasted into anagent chat and sent to the model. October 6, 2026 at04:07:57 UTC Unpinned MCPserver An MCP server runs from anunpinned, mutable version. October 6, 2026 at04:05:39 UTC Destructivecommand An agent ran rm -rf outside theproject workspace. October 6, 2026 at03:54:17 UTC Kirin User Coverage Over Time Total Users 1833 Active Users 1702 Active Users Total Users Last 30 days Policies Coverage 89% Detection Policies Detects active attacks, malicious content, and security threats. These policies are enabled by default to provide immediate protection. 8 enabled out of 9 100% AI Agent Instructions Your rules for how AI coding agents should behave. Kirin audits instruction files (such as CLAUDE.md and .cursorrules) against this catalog and reports… 58 enabled out of 60 100% Allow/Block Lists Manage Allow and Block lists. 2 enabled out of 2 Top MCP Servers by Usage postgres 1803 playwright 1408 github 1049 sentry 636 stripe 543

Model risk now includes the agent's actions.

An agent with production access can execute a destructive change, a poisoned dependency can reach a payments service, and a credential can leave in a prompt. Knostic stops each at the tool call and records the decision for SOX, PCI DSS, DORA, and your model risk framework.

How Knostic works in financial services

Production safety

Before Knostic

An agent tidying data drops the live orders table. Transactions fail and errors climb before anyone is paged.

After Knostic

Kirin denies the destructive command before it executes, tells the developer why, and logs a Prevented alert for the SOC.

Secure generated code

Before Knostic

Code for a payments endpoint ships with no auth check, string-built SQL, and a vulnerable dependency.

After Knostic

Agents follow your secure-coding rules and threat-model first. OpenAnt finds the exploitable paths that remain.

Regulatory inventory

Before Knostic

Which AI systems are in use? Nobody can produce the list.

After Knostic

A live inventory of agents and models by team, ready for the register.

Key capabilities

Action guardrails

Destructive and data-moving operations blocked or escalated before execution.

Secret and client-data detection

Keys, tokens, and personal or account data caught before they leave the agent.

Secure AI SDLC

Coding rules enforced in the agent, hallucinated packages blocked, OpenAnt vulnerability discovery.

Supply-chain verdicts

AgentMesh ratings on skills, MCP servers, and extensions.

Audit evidence

Decision logs and inventory for SOX, PCI DSS, DORA, and model risk reviews.

Segregated policies

Different allowances for trading, risk, and engineering from one policy set.

Frequently asked questions

With an inventory of AI systems, enforced controls on agent actions, and logs of every decision. Knostic provides control evidence; it is not a certification.

Yes. Policies distinguish read, write, and destructive operations and can be scoped to systems and environments.

No. Kirin runs inside the agent and only interrupts a policy violation, with the reason and a safe path.

To the Kirin dashboard and your SIEM, with full context for the SOC.