Capabilities
A 67-threat matrix plus content rules, across everything the agent touches: what's typed, what it reads, what it passes to a tool, and what it says back.
Just shipped.
Four capabilities that landed recently — each on-device and content-free, and each honest about where its enforcement reaches today.
browser-ext/ in the open-source repo, not yet in an extension store — same content-free contract as the endpoint agent.moorai scan at a skill, agent, or MCP config before you install it and get a verdict — clean, caution, review, or do-not-install — from the same on-device engine that enforces at runtime. Reverse shells, credential reads, poisoned MCP descriptors and injected instructions are caught in the artifact, not after it’s running. The verdict is the engine’s own enforcement decision, not an invented score.The short version.
Every claim as a straight yes or no.
Real prompts,
caught in the act.
A sample of what MoorAI recognizes — a 67-threat matrix plus content rules, across everything the agent touches: what's typed, what it reads, what it passes to a tool, and what it says back. Each badge shows a representative response; you decide what every category actually does per policy: coach, alert, block, or require a signed justification.
How well it does that is measured on a corpus anybody can download: the Agentic Security Benchmark — 286 attack samples and 875 benign, Apache-2.0, five AMTSO attack vectors, with the scoring arithmetic and the false-positive line published beside every recall figure. Scored runs are on the leaderboard.
claude -p CLI guard masks flagged spans before printing.Prompts, files and MCP tool calls,
reviewed before the AI sees them.
Before anything an employee types reaches an AI tool, MoorAI checks it right there on the computer — against the rules you set. And it doesn't stop at the prompt: the same local engine checks the files an agent reads into its context, the arguments it passes to MCP tools, and the answers it sends back. Anything sensitive gets flagged or stopped, and what your people actually write never leaves the machine.
.env full of live keys is caught before that content ever lands in the model's context. Full enforcement on Claude Code via its PreToolUse hooks; Codex and Copilot CLI are detection-only, since they expose no equivalent deny hook.mcp__* tool call for secrets and PII before the call runs, and blocks per policy. The MCP surface is where agents quietly hand data to third-party servers — this is the check on that path.claude -p CLI guard masks flagged secret spans before they're printed — so a key the agent echoes out of a config file doesn't land in a terminal log or a pasted transcript.system: directive, buried in a file the agent will read later, is exactly the kind of delayed hijack this catches.components[] shape for GRC, audits, and third-party risk reviews.Compliance & Regulation.
MoorAI maps its threat model and content-free telemetry to the AI-security frameworks your auditors ask about — and rolls it into a board-ready readiness report and an on-device AIBOM for the EU AI Act. So “how do you govern AI use?” has an evidenced answer, drawn from redacted signals — never a window into what anyone typed.
An AI-readiness report
your board can read.
MoorAI rolls its content-free telemetry into a single board-level report: a composite trust score, shadow-AI exposure, endpoint posture, framework control-mapping, and a data-lineage-by-agent trail — all built from redacted signals, never prompt content. Evidence of how your organization governs AI, without a window into what anyone typed.
See the full layout — composite score, framework-mapping summary, and a data-lineage-by-agent table — rendered with example data.
Discover the shadow agents already on your dev laptops.
Start here: you almost certainly have unmanaged Claude Code, Cursor, and Copilot installs running on developer machines right now — and zero visibility into what they read, send, or exfiltrate. That's the first job. MoorAI inventories every AI agent, app, account, MCP server, and browser extension on each device — from redacted, content-free signals — then lets you govern it: which agents and MCP servers are approved, and what each is allowed to do. Shadow AI stops being a blind spot, and unsanctioned agents stop being an open exfiltration path.
Review it
on the device.
Coach, alert, or block — before the prompt reaches the agent.