As AI agents move from experiment to daily workflow, they're planning tasks, executing shell commands, calling MCP tools, and installing packages directly on endpoints, often with the full credentials and access of the humans they assist. Because traditional endpoint tools were never built to assess these AI artifact risks, security teams are left with a growing blind spot regarding what their AI agents can actually do and who can control them.
Koi Agentic Endpoint Security (AES) closes that gap. Since Koi's acquisition, we've remained focused on execution. Over the past several releases, we've shipped major advances across discovery, runtime enforcement, and remediation, giving teams a complete lifecycle view of every agent, extension, and account running across their environment. Here's a look at some of the key innovations and what they mean for your organization.
See Every Agent, Not Just the Ones You Already Know About
Static lists of known agents guarantee a blind spot, because the next widely adopted coding agent won't appear on anyone's list on the day it launches.
Koi AES prevents these blind spots using an LLM-based classifier that automatically flags autonomous AI actors across your entire inventory. It identifies true agents versus agent platforms that are products with agentic features added on, and this visibility applies across all item types and deployment methods. As new tools continuously emerge, this capability ensures that you keep pace, surfacing the next “OpenClaw” the moment it shows up on any endpoint.

Trace Every Agent Session from Start to Finish
A stream of individual events makes it difficult to understand what an agent was actually doing and why.
Koi AI Detection & Response (AIDR) organizes agent activity around continuous developer-agent sessions rather than fragmented event feeds. Each session surfaces a complete operational picture: the associated user account, the specific LLM models involved, and the exact AI agent extensions deployed (such as skills, plugins, and MCPs). Combined with a chronological timeline of shell execution, file access, and blocked actions, AIDR gives admins the full context required to evaluate actual usage patterns and shape effective governance policies.

Detect Shadow AI Before Your Data Leaves the Building
Employees are signing into coding agents with personal accounts on corporate endpoints, and that activity sits completely outside the organization's control. This level of visibility is critical because AI agents operate with broad endpoint access like reading and writing files, executing shell commands, and invoking tools. When an agent runs under a personal user account, that activity occurs entirely outside your organization's control, creating severe data leakage risks. Agents routinely ingest source code, internal data, and customer information as context; under an ungoverned personal account, this data flows outside your perimeter. Additionally, free and personal subscription tiers often use conversation data for model training by default, unlike enterprise agreements with strict no-training commitments.
Koi AES now detects personal account usage across Claude Code, Cursor, Codex, and Antigravity, flagging any session where the account's email domain doesn't match the organization's. Security teams get per-session user detection, personal account classification, subscription tier view, and a dedicated filter to surface personal shadow AI activity that enables them to instantly detect any usage prone to data exfiltration.


Define Exactly What Your Agents Can and Can't Do
Discovery tells you what's happening. Runtime policy is what stops the risky action before it becomes an incident.
Agent runtime custom policies let admins define their own rules across multiple applications like Cursor, Claude Code, and Antigravity, to restrict shell execution, file access, MCP tools, skills, and network requests without compromising developer productivity. Two enforcement modes are available: block, which denies the action outright, and ask, which pauses the agent for explicit user approval to ensure user intent before the action is taken. When a policy triggers, a custom block message appears directly within the agent chat interface to inform end users on why an action was restricted. To maintain seamless workflows, developers can easily request policy exclusions or obtain necessary approvals directly from their interface.

Align AI Extension Capabilities with True Business Intent
Traditional security tools tell you if code is broken, but they can't tell you if an AI plugin is lying about what it does. An AI-native analysis bridges the gap by decoding how extensions actually alter agent decision-making at runtime.
AI extensions do more than run code. They directly shape an agent's permissions, system access, and operational boundary. With Koi’s AI-native analysis, it performs multidimensional behavioral analysis across intent, expected behavior, capabilities, and permissions to detect misleading plugin descriptions, unapproved shell executions, and unauthorized data transmission. By correlating traditional static code and dependency checks with agentic behavior models, Koi AES spots risky capabilities like secret harvesting, prompt injection susceptibility, and dynamic tool generation before they can derail production environments. The result is a unified security assessment that keeps developer workflows fast while ensuring every active extension strictly respects organizational guardrails.
Remove Risk That's Already on the Endpoint
Visibility and policy matter most when they connect to action, and until now, cleanup after discovery required manual work from the security team.
Koi AES's remediation capabilities now span the full agentic supply chain. AI plugin remediation removes a flagged Claude Code plugin's entire footprint from an endpoint, deleting it from user settings, the local plugin directory, and all associated files. NPM package remediation goes further, removing critical-risk packages already installed after campaigns like Shai-Hulud, clearing caches, and blocking re-introduction through the registry proxy, all without manual intervention from your team.

More Innovations Across Koi Agentic Endpoint Security
Beyond the major releases above, Koi AES has shipped numerous enhancements to strengthen discovery, sharpen enforcement, and simplify governance for practitioners.
Discovery and Visibility
- Binaries Inventory and Execution Logs (macOS): Full visibility into every binary launched across the macOS fleet, integrated with Santa and capturing the executor, endpoint, file path, and SHA-256 hash.
- Claude Connectors Discovery: Visibility into every local connector installed via the Claude Desktop marketplace, including source, version, install count, and risk data like security findings and tools exposed.
- Cloned Git Repos Discovery Visibility into git repositories cloned across your fleet enriched with publisher, stars, license, and risk signals for public GitHub repos.
App Control Enforcement
- Binary Block and Alert Policies with Impact Check: Define custom binary execution policies and run an Impact Check before applying one, to see exactly which binaries and endpoints it would affect.
- Risky Path Guardrail: Automatically blocks binary execution from untrusted locations such as /tmp, /var/tmp, and $TMPDIR.
Governance and Remediation
- Claude Connectors Marketplace Governance: Set allow and block prevention policies for Claude Desktop connectors, approve developer requests for blocked connectors, and remediate connectors already installed on managed endpoints.
- New Deployment Portal: A single, wizard-driven flow for endpoint deployment across macOS, Windows, and Linux, and network routing through Quick Trust or native SASE integrations.
Give Your Organization Speed. Give Your Security Team Control.
Agentic AI is already part of the default workflow, and it moves faster than most security programs can track. Koi Agentic Endpoint Security helps teams see every agent, define what it's allowed to do, and remove what shouldn't be there, all without slowing innovation down.
Ready to see it in action? Check out Koi Agentic Endpoint Security to learn more.