Every component your agent depends on is scanned against known threat patterns. Approved components get an Agent SBOM. The rest are blocked at intake.
- Prompt-injection pattern detection
- Embedded-secret discovery
- Malicious tool-definition flagging
- Agent SBOM — signed, versioned, traceable
- MCP allowlist gateway
OutputsSBOM JSON · scan report · webhook on policy violation