ATLAS agentic-technique coverage, vendor by vendor
What 43 AI-security vendors document in their own published material against the 76 MITRE ATLAS 2026.09 techniques tagged Agentic AI. 27 are documented by none of them and by no MoorAI rule. 10 of those are defence-side techniques, not adversary preparation. Every credit carries the URL of the vendor page it came from and a verbatim quote, and MoorAI is scored the same way. The capability-by-capability table for the same vendors is on MoorAI vs the field →
MITRE's ATLAS 2026.09 release tags 76 top-level techniques with the platform Agentic AI. That list — MITRE's tag, applied mechanically, not our own selection — is read here against what 43 AI-security vendors have published. Every credit rests on the vendor's own page and a sentence quoted from it verbatim.
The interesting result is not the ranking. It is the shape of the map: a handful of techniques draw most vendors, nine are claimed by exactly one vendor each, and 27 of the 76 are claimed by no product we read.
MITRE ATLAS agentic techniques, who documents what
One row per technique, most-documented at the top; one block per vendor along the row, so its length counts the 43 vendors. MoorAI has its own column at the left of the rows. Hover a block for the technique and the product.
Coverage collapses fast: 49 of the 76 techniques have any at all, and most of those rest on one or two products.
A dashed block is coverage documented with a limit the product states itself (220 of 548). An empty cell in the green column means MoorAI covers nothing there — 18 of 49. The same data as text is the evidence table below.
Scroll sideways →
No row at all — 27 techniques no product here documents
None of the 43 vendors reviewed documents these, and MoorAI's rule base carries none of their ids. 10 are defence-side techniques. 6 sit in Discovery or AI Model Access; ATLAS calls Discovery post-compromise and neither tactic preparation, so they are listed apart rather than set aside. 11 are adversary preparation, by ATLAS's own definitions of Reconnaissance, Resource Development and AI Attack Adaptation.
10 defence-side
- AML.T0031 Erode AI Model Integrity
- AML.T0046 Spamming AI System with Chaff Data
- AML.T0059 Erode Dataset Integrity
- AML.T0071 False RAG Entry Injection
- AML.T0076 Corrupt AI Model
- AML.T0094 Delay Execution of LLM Instructions*
- AML.T0096 AI Service API
- AML.T0111 AI Supply Chain Reputation Inflation
- AML.T0120 AI Artifact Repository
- AML.T0130 AI Agent Response Biasing
6 Discovery or AI Model Access
11 adversary preparation
- AML.T0002 Acquire Public AI Artifacts
- AML.T0005 Create Proxy AI Model
- AML.T0016 Obtain Capabilities
- AML.T0017 Develop Capabilities
- AML.T0042 Verify Attack
- AML.T0064 Gather RAG-Indexed Targets
- AML.T0065 LLM Prompt Crafting
- AML.T0066 Retrieval Content Crafting
- AML.T0116 Autonomous Reconnaissance
- AML.T0117 Autonomous Attack-Path Adaptation*
- AML.T0124 Autonomous Attack Orchestration
* Described in MoorAI's published prose, which the prose review credits, though no shipped rule carries the id: AML.T0094, AML.T0117.
Where everyone is standing
The most-documented techniques are the ones with obvious product shape — something leaves, something gets injected, a tool gets called. Twenty-five are documented by ten or more of the 43 vendors.
Scroll sideways →
| Technique | Vendors documenting it |
|---|---|
| AML.T0053 AI Agent Tool Invocation | 36 / 43 |
| AML.T0051 LLM Prompt Injection | 35 / 43 |
| AML.T0057 LLM Data Leakage | 33 / 43 |
| AML.T0086 Exfiltration via AI Agent Tool Invocation | 30 / 43 |
| AML.T0054 LLM Jailbreak | 29 / 43 |
| AML.T0110 AI Agent Tool Poisoning | 22 / 43 |
| AML.T0103 Deploy AI Agent | 21 / 43 |
| AML.T0084 Discover AI Agent Configuration | 19 / 43 |
| AML.T0010 AI Supply Chain Compromise | 16 / 43 |
| AML.T0048 External Harms | 16 / 43 |
| AML.T0132 Misconfigured or Publicly Exposed AI Services | 16 / 43 |
| AML.T0133 Discover AI Agent Runtime Capabilities | 16 / 43 |
| AML.T0011 User Execution | 15 / 43 |
| AML.T0083 Credentials from AI Agent Configuration | 15 / 43 |
| AML.T0101 Data Destruction via AI Agent Tool Invocation | 15 / 43 |
| AML.T0098 AI Agent Tool Credential Harvesting | 14 / 43 |
| AML.T0056 Extract LLM System Prompt | 13 / 43 |
| AML.T0068 LLM Prompt Obfuscation | 13 / 43 |
| AML.T0081 Modify AI Agent Configuration | 13 / 43 |
| AML.T0099 AI Agent Tool Data Poisoning | 13 / 43 |
| AML.T0007 Discover AI Artifacts | 12 / 43 |
| AML.T0034 Cost Harvesting | 12 / 43 |
| AML.T0118 Autonomous AI Agent Communication | 12 / 43 |
| AML.T0085 Data from AI Services | 11 / 43 |
| AML.T0080 AI Agent Context Poisoning | 10 / 43 |
Coverage is less concentrated than the top of that table suggests. The four most-documented techniques hold 134 of the 517 vendor credits, 26%, and it takes the eleven most-documented to account for half. The other half is spread across the remaining 33 techniques that any vendor documents.
Counts in this table are out of the 43 vendors, and so is the length of every row in the chart above. MoorAI has its own column at the left of those rows — filled where our rule base maps the technique, left deliberately empty where it does not, so the column reads as a floor with holes in it rather than quietly closing up. There are 18 holes in it. If you are buying, the top of this table is the part of the market where you have genuine choice and can compare on quality rather than existence.
Coverage by product
The same 548 credits, read the other way: one row per product instead of one row per technique. No vendor documents more than 26 of the 76 techniques, 34% of the set. The median vendor documents 11, and 18 of the 43 document fewer than ten. The scale is the whole 76, not the leader, so the empty length to the right of every bar is the part of the framework where we found nothing published for that product.
MoorAI's row is counted from its rule base, as its column is in the chart above, not by the prose method the vendor rows use. It is not like-for-like with the rows around it; the note under the table gives the figures the prose method produces.
Techniques documented, per product, of 76
documenteddocumented, with a limit the product states itself
Scroll sideways →
| Product | Documented (of 76) | Of which bounded | No other vendor documents | Share of the 76 |
|---|---|---|---|---|
| MoorAI*rule base | 31 | 16 | 5T0131 T0067 T0092 T0134 T0035 | 41% |
| Pillar Securityadded 27 Sep | 26 | 8 | 0 | 34% |
| Zenity | 23 | 3 | 1T0108 | 30% |
| Lasso Securityadded 27 Sep | 23 | 4 | 0 | 30% |
| Operant AI | 23 | 6 | 0 | 30% |
| Straiker | 22 | 3 | 1T0100 | 29% |
| Lakera‡partial review | 21 | 10 | 2T0062 T0082 | 28% |
| Aktoadded 1 Oct | 21 | 12 | 0 | 28% |
| Enkrypt AIadded 1 Oct | 20 | 8 | 0 | 26% |
| Noma Securityadded 1 Oct | 20 | 10 | 0 | 26% |
| PointGuard AIadded 1 Oct | 19 | 7 | 0 | 25% |
| NeuralTrustadded 1 Oct | 19 | 9 | 0 | 25% |
| Endor Labs | 18 | 11 | 2T0060† T0115 | 24% |
| Netskope | 17 | 7 | 0 | 22% |
| SentinelOne‡partial review | 15 | 6 | 0 | 20% |
| Backslash Security | 14 | 1 | 0 | 18% |
| Certiv | 14 | 2 | 0 | 18% |
| WitnessAIadded 27 Sep | 14 | 5 | 0 | 18% |
| HiddenLayeradded 1 Oct | 14 | 7 | 0 | 18% |
| Salt Security | 12 | 2 | 1T0006 | 16% |
| Holistic AIadded 1 Oct | 12 | 6 | 0 | 16% |
| Airiaadded 1 Oct | 12 | 7 | 0 | 16% |
| Levo.aiadded 1 Oct | 11 | 5 | 0 | 14% |
| Aurascapeadded 1 Oct | 11 | 6 | 0 | 14% |
| Cycode | 10 | 4 | 0 | 13% |
| Craniumadded 1 Oct | 10 | 7 | 1T0061† | 13% |
| Forcepoint | 9 | 3 | 0 | 12% |
| DeepKeepadded 1 Oct | 9 | 5 | 0 | 12% |
| Permisoadded 27 Sep | 9 | 6 | 0 | 12% |
| BigID | 8 | 3 | 0 | 11% |
| CyCraftadded 1 Oct | 8 | 3 | 0 | 11% |
| Bifrost Edge | 7 | 3 | 0 | 9% |
| Onyx Securityadded 1 Oct | 7 | 4 | 0 | 9% |
| Vijiladded 1 Oct | 6 | 2 | 0 | 8% |
| Trustwiseadded 1 Oct | 6 | 3 | 0 | 8% |
| Virtue AIadded 1 Oct | 6 | 3 | 0 | 8% |
| Singulr AIadded 1 Oct | 4 | 1 | 0 | 5% |
| Kitecyber | 4 | 2 | 0 | 5% |
| MIND | 4 | 3 | 0 | 5% |
| Harmonic Security | 3 | 1 | 1T0040 | 4% |
| Above Securityadded 1 Oct | 2 | 2 | 0 | 3% |
| dope.security | 2 | 2 | 0 | 3% |
| Rig Securityadded 1 Oct | 2 | 2 | 0 | 3% |
| Ent | 0 | 0 | 0 | 0% |
* MoorAI's 31 (16 bounded) come from its rule base: a technique counts when a shipped rule carries its ATLAS id. Scored the way the vendors are, from published prose only, MoorAI documents 31; with every credit traceable to the one README bullet that names ATLAS ids removed, 26. The rule base is MoorAI agent v1.1.0’s, released on 1 October 2026. Its ATLAS mapping is unchanged since agent v0.96.0, released on 26 September, after the original vendor read of 20 September and before the four vendors added on 27 September and the twenty vendors added on 1 October were read; the rules v0.96.0 added are listed in the 26 September update. The method is in We ran the method against ourselves. Its “no other vendor” count is the techniques none of the 43 vendors documents.
† Also documented by MoorAI. That column counts the 43 vendors only, as the single-vendor table below does: 9 techniques, 2 of which MoorAI's rule base also holds.
Marked added 27 Sep: Lasso Security, Permiso, Pillar Security and WitnessAI, read on 27 September and added to the study after the original read of 20 September. They were read by the same method; the expansion notes say what changed.
Marked added 1 Oct: Above Security, Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Rig Security, Singulr AI, Trustwise, Vijil and Virtue AI, read on 1 October and added to the study after the original read of 20 September. They were read by the same method; the expansion notes say what changed.
‡ Partial review: this vendor's material had a shallower read than the others, so its count is a floor rather than a comparable figure. The reason is recorded with its sources.
Two in five published credits come with a limit attached
Counting cells hides something. Of the 548 credits in this review, 220 are what the data calls bounded — coverage the product documents together with a limit it states itself. In the chart those blocks are drawn hollow and dashed. Treating them as equal to a flat claim would overstate two fifths of the market.
The qualification is uneven, and it does not simply follow the crowd:
Scroll sideways →
| Technique | Blocks | Of which bounded | Share bounded |
|---|---|---|---|
| AML.T0053 AI Agent Tool Invocation | 37 | 18 | 49% |
| AML.T0051 LLM Prompt Injection | 36 | 9 | 25% |
| AML.T0057 LLM Data Leakage | 34 | 4 | 12% |
| AML.T0086 Exfiltration via AI Agent Tool Invocation | 31 | 13 | 42% |
| AML.T0054 LLM Jailbreak | 30 | 8 | 27% |
| AML.T0110 AI Agent Tool Poisoning | 23 | 11 | 48% |
| AML.T0103 Deploy AI Agent | 21 | 18 | 86% |
| AML.T0084 Discover AI Agent Configuration | 19 | 15 | 79% |
| AML.T0010 AI Supply Chain Compromise | 17 | 6 | 35% |
| AML.T0133 Discover AI Agent Runtime Capabilities | 17 | 5 | 29% |
| AML.T0048 External Harms | 17 | 2 | 12% |
| AML.T0132 Misconfigured or Publicly Exposed AI Services | 16 | 5 | 31% |
| AML.T0011 User Execution | 16 | 4 | 25% |
| AML.T0101 Data Destruction via AI Agent Tool Invocation | 16 | 4 | 25% |
| AML.T0083 Credentials from AI Agent Configuration | 15 | 11 | 73% |
| AML.T0098 AI Agent Tool Credential Harvesting | 15 | 11 | 73% |
| AML.T0081 Modify AI Agent Configuration | 14 | 9 | 64% |
| AML.T0056 Extract LLM System Prompt | 14 | 5 | 36% |
| AML.T0068 LLM Prompt Obfuscation | 14 | 4 | 29% |
| AML.T0099 AI Agent Tool Data Poisoning | 14 | 2 | 14% |
| AML.T0034 Cost Harvesting | 13 | 6 | 46% |
| AML.T0118 Autonomous AI Agent Communication | 13 | 5 | 38% |
| AML.T0007 Discover AI Artifacts | 12 | 10 | 83% |
| AML.T0085 Data from AI Services | 11 | 4 | 36% |
| AML.T0080 AI Agent Context Poisoning | 11 | 3 | 27% |
Tool invocation ties with deploying an agent for the most bounded claims — eighteen of its thirty-seven arrive with a stated limit, and eighteen of deploying an agent’s twenty-one. Tool invocation is the cell most likely to be read as solved and least likely to be. But crowding is not the pattern: prompt injection and data leakage are nearly all flat claims. The highest shares sit on techniques about an agent’s configuration and credentials — deploying an agent, harvesting tool credentials, modifying agent configuration, credentials in agent configuration, discovering agent configuration — and on discovering AI artifacts, where vendors often say themselves that they find things rather than stop them.
By product, the share varies enormously: dope.security 2 of 2, MIND 3 of 4, Permiso 6 of 9, Endor Labs 11 of 18, Lakera 10 of 21, MoorAI 16 of 31. Read a high proportion as candour, not weakness. A bounded cell exists because a vendor wrote down where its coverage stops; a vendor that never qualifies anything is not necessarily covering more ground, it may simply be writing less carefully. Every product here has at least one bounded cell except Ent, which has no cells at all.
Why nobody can count their agents
Four techniques on the map are the same job from different angles: AML.T0132 exposed AI services (16 of 43), AML.T0084 discover agent configuration (19), AML.T0103 deploy AI agent (21) and AML.T0007 discover AI artifacts (12). Inventory, posture and discovery — knowing what exists before defending it.
Even the best-covered of those has only about half the vendors here publishing on it.
The underlying difficulty is that some products count agents, some map their permissions, some watch what they actually do, and buyers assume one implies the others. ATLAS agrees — it keeps those as separate techniques, and AML.T0133 is defined as learning an agent’s capabilities without access to its configuration, which is exactly what makes it a different technique from AML.T0084. Three rows in this chart, not one.
The 27 no product here documents
27 of the 76 techniques are documented by none of the 43 vendors, and no MoorAI rule carries their ids. Counting vendors alone it is 32, because five techniques are held by MoorAI’s rule base and no one else: AML.T0131 Crafted AI Assistant Links and AML.T0134 AI Targeted Cloaking, and three whose rules shipped in agent v0.96.0 after this study and because of it, AML.T0092, AML.T0067 and AML.T0035 (see the update). A fourth rule from that release, for AML.T0061 LLM Prompt Self-Replication, has company: Cranium, added on 1 October, documents a static check for it in agent configuration files. The chart lists all 27 by id and name under “No row at all”.
“Nobody” needs two qualifications. It means nobody in this sample. Forty-three vendors plus MoorAI is not the market, and products outside it publish material on some of these techniques: Microsoft on AI recommendation poisoning (AML.T0130) and on a backdoor that uses an AI service API for command and control (AML.T0096), Cisco’s open-source skill scanner on instructions deferred to a later turn (AML.T0094), and ReversingLabs on corrupted model files (AML.T0076). Those vendors were not read against the whole framework, so they are not in the chart. And MoorAI’s own prose describes two of the 27, AML.T0094 and AML.T0117, which the prose review below credits; no shipped rule is mapped to them, so the chart’s MoorAI column, which counts rules, leaves them empty.
The 27 split three ways by ATLAS’s own tactic definitions.
11 are adversary preparation, in Reconnaissance, Resource Development and AI Attack Adaptation: acquiring public AI artifacts, developing capabilities, crafting a prompt or retrieval content, verifying an attack works, reconnaissance. They are on the map because ATLAS models the attacker’s whole path, not because they are a product gap. It is not true, though, that defensive products never claim this ground: vendors document nine techniques whose tactics all sit in these three or the two below, four of them in the preparation tactics themselves, led by autonomous AI agent communication (AML.T0118, twelve vendors).
6 sit in Discovery or AI Model Access: discovering a model family, its outputs or the LLM’s system information, and three kinds of model access. ATLAS does not call these preparation; it describes Discovery as post-compromise. They are listed apart rather than set aside. Neighbouring Discovery techniques are among the most documented in the review, and system-information discovery overlaps system-prompt extraction (AML.T0056), which thirteen vendors document; under the one-mechanism rule those sentences earn the extraction cell only.
The remaining 10 are defence-side techniques that a security product could plausibly address, and nobody in this set has published that they do. By tactic, the uncovered techniques fall like this:
Scroll sideways →
| Tactic (first listed) | Techniques | Documented by no product | Share | ATLAS class |
|---|---|---|---|---|
| AI Attack Adaptation | 8 | 6 | 75% | adversary preparation |
| AI Model Access | 4 | 3 | 75% | Discovery / model access |
| Command and Control | 3 | 2 | 67% | defence-side |
| Reconnaissance | 3 | 2 | 67% | adversary preparation |
| Resource Development | 5 | 3 | 60% | adversary preparation |
| Impact | 9 | 4 | 44% | defence-side |
| Discovery | 7 | 3 | 43% | Discovery / model access |
| Defense Evasion | 11 | 4 | 36% | defence-side |
By count, Defense Evasion and Impact tie for the most undocumented defence-side techniques, four of Defense Evasion’s eleven and four of Impact’s nine. By share, Command and Control is emptier, two of three. Defense Evasion is not empty: jailbreaks, prompt obfuscation, supply-chain rug pulls and triggers in multimodal inputs all have vendor coverage, and AI-targeted cloaking has a MoorAI rule. Two of the four that have nothing are about an attack that has already landed and is hiding — a false entry nested in the index, instructions set to fire later. The other two are about getting past a check: a model file corrupted to slip past a scanner, reputation inflated in a supply chain. Chat history rewritten and output dressed to look trustworthy each have a bounded MoorAI rule, written after the study.
Four of Impact’s nine techniques have nothing either: eroding model integrity, eroding dataset integrity, biasing an agent’s responses, flooding a system with chaff. These are outcomes an attacker actually wants, and no vendor here documents defending against them.
Nine techniques with exactly one vendor
Nine more are documented by a single vendor. A monoculture is worth knowing about when you are building a stack.
Scroll sideways →
| Technique | The only vendor documenting it |
|---|---|
| AML.T0061 LLM Prompt Self-Replication | Cranium |
| AML.T0060 Publish Hallucinated Entities | Endor Labs |
| AML.T0115 Publish Poisoned AI Artifacts | Endor Labs |
| AML.T0040 AI Model Inference API Access | Harmonic Security |
| AML.T0062 Discover LLM Hallucinations | Lakera |
| AML.T0082 RAG Credential Harvesting | Lakera |
| AML.T0006 Active Scanning | Salt Security |
| AML.T0100 AI Agent Clickbait | Straiker |
| AML.T0108 AI Agent | Zenity |
A low count is usually a category, not a weakness
The vendors at the bottom of this map are mostly data-loss-prevention and insider-risk platforms. That is not a verdict on them. ATLAS agentic techniques describe an adversary acting against a model or an agent; a DLP platform is built to stop sensitive data leaving regardless of which technique moved it. Most of this framework is simply not its subject.
Two vendors say so themselves, and their word is taken over their own marketing. MIND, on a post about an autonomous-agent breach:
“MIND doesn’t patch template-injection flaws or contain a sandbox escape. No data loss prevention platform does.”
And dope.security, which publicly assigns MCP security, prompt injection and model security to others. Where a vendor draws its own boundary, the boundary wins — credits were removed on the strength of those statements.
Corpus size is not the explanation either. MIND publishes 184 pages and roughly 174,000 words, a body of material comparable to vendors scoring four times higher. It writes a great deal; it writes about something else.
We ran the method against ourselves
MoorAI’s column is counted differently from every vendor’s row: from a rule base that carries explicit ATLAS ids, where a technique counts when a shipped rule is tagged with it. Every vendor row is a prose review.
To find out what that difference is worth, MoorAI was scored the way vendors are — published prose only, no access to the rule base. It came out at 31, against the 27 the rule base gave on the read date. Discarding every credit traceable to one README bullet that names ATLAS ids outright, it is still 26.
So on the read date the prose method was the more generous of the two. Eight of those 31 are techniques our own rule base does not claim — inventory, posture and visibility sentences that a reviewer credits because that is what Operant and Lakera were credited for, and that a rule base has no rule for.
The rule base now gives 31, level with the prose count, and the two are no longer like-for-like in time. MoorAI agent v0.96.0, released on 26 September, added rules for AML.T0061, AML.T0092, AML.T0067 and AML.T0035, the last three bounded to local transcript files, links, and model files moved in one command. They were written after this study, because of the gaps it found; they did not exist when the prose was read, and the prose review has not been re-run since. The current release, agent v1.1.0, carries the same ATLAS mapping, and it is the rule base the chart’s MoorAI column is drawn from.
Our documentation is written in this framework's language, in units about the size of one ATLAS technique. A prose review rewards that shape. A vendor whose documentation is written for buyers gets credited only where its wording happens to coincide with a technique name, and is undercounted for it. That is the bias in this map, and it favours us. Read the whole thing as a map of what each vendor has written down, not as a measurement of what each product does.
Every technique, every vendor: the evidence
MITRE ATLAS tags every technique with the kinds of system it applies to, and one of those tags is Agentic AI. Taking that tag as the filter gives 76 techniques in the 2026.09 release — the denominator of every count on this page. The set is MITRE’s, not ours, which is the point: it was not drawn around what any product here happens to do. Technique IDs, names and definitions come from the ATLAS 2026.09 data release (Apache‑2.0), published 2026-09-15. The table below is every cell of the study, and the chart above drawn as text.
How each cell was scored — and what the score is not
- Where the 76 come from
- Every top-level ATLAS 2026.09 technique whose own
platformsfield lists Agentic AI. Sub-techniques are not separate rows — a claim about one counts toward its parent. Applying someone else’s tag mechanically is what keeps the denominator honest: it admits techniques nobody covers, and it drops two that an earlier draft of this page scored, including AML.T0012, which the MoorAI rule base maps to. The rule costs MoorAI a cell rather than buying it one. - The comparison is asymmetric, in MoorAI’s favour — discount it accordingly
- MoorAI’s count is derived from a rule base whose rules carry ATLAS ids, so nothing it addresses can be missed. Every competitor’s count comes from marketing and documentation prose that mostly never mentions ATLAS, so it is credited only where the wording happens to line up with a technique. Those two methods do not produce comparable numbers, and the gap flatters MoorAI. A vendor scoring lower here has not been shown to do less; it has been shown to have written less that maps onto this framework.
- When one mechanism covers several techniques
- A technique is credited when the evidence describes a distinct implemented mechanism that addresses that technique’s definition. One piece of evidence may credit more than one technique only when it implements each distinctly — never when one technique restates, contains, or is a likely consequence of another. So a single vague “discover your AI” sentence still earns one cell, not five; but a documented mechanism that genuinely does several separate jobs earns each of them. This rule was applied to every row in the table, MoorAI’s included. MoorAI’s row is re-derived under it: 9 of its 77 rules map to more than one technique.
- When a vendor contradicts itself, the disclaimer wins
- Vendors publish boundaries as well as claims, and the boundaries are honoured here over that same vendor’s marketing. A vendor writing “we do not claim this”, assigning a capability to a named competitor’s lane, or labelling it roadmap or not-yet-enforced, removes the cell — a company disowning a capability is stronger evidence than a sentence elsewhere implying it has one. Where the two are dated, the later statement governs; where a claim is newer than the disclaimer and describes something narrower that the disclaimer does not cover, it stands, with the boundary recorded on the cell. One vendor here lost two cells this way, and the rule cost it its position rather than us ours. A stated scope limit — only some hosts, only the hosted product, fails open, tests rather than enforces — keeps the cell and adds the limit instead. That search was not equally thorough for every vendor: two of the six reviews did not report, and their vendors’ boundaries were recovered from collected material rather than a dedicated pass, so “no disclaimer found” is less firmly established for those than for the rest. One credited capability was also removed for the opposite reason — not a disclaimer but an absence: the technology it named appears nowhere on that vendor’s site, so the credit had no evidence behind it at all.
- Governing usage of AI is not defending against an adversary
- Shadow-AI discovery, data-loss prevention and app control applied to AI traffic are real capabilities, but they are not coverage of an ATLAS adversary technique, and they earn no cell here. Explaining an attack is not covering it either: a blog post defining prompt injection is education, a page saying the product detects or blocks it is a claim, and only the second counts.
- Three states, and no “absent”
- A cell is documented, documented with a stated limit, or not described. A bounded cell still counts — it is coverage with an edge, and the edge is written on the row. There is deliberately no “absent” state: a vendor whose material is silent on a technique may well handle it. Nothing on this page says a named vendor is exposed to anything.
- What a stated limit means
- The bounded state is open to every product here and several vendors carry one — a capability routed to a third party rather than native, enforcement on only some hosts, or wording that describes red-team testing rather than runtime enforcement. MoorAI carries the most of them, and that is a fact about the evidence rather than about the products: MoorAI is scored from its own implementation, where the boundary is known and written down, while a competitor is scored from marketing copy, which rarely says where a capability stops. So read an unqualified documented in a vendor column as “their material claims this”, never as “this is complete” — on that evidence nobody can tell, and the absence of a limit is not evidence of its absence.
- This is a documentation review, not a test
- Competitor cells were read from each vendor’s own published material — product pages, public documentation, vendor blogs — on 2026-09-20, except 4 cells added in a correction on 2026-09-26, each dated in its source line below. 4 vendors were added to the review later, read on 2026-09-27 by the same method: Lasso Security, Permiso, Pillar Security, WitnessAI. 2 vendors were added to the review later, read on 2026-10-01 by the same method: Above Security, Rig Security. 18 vendors were added to the review later, read on 2026-10-01 by the same method: Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Singulr AI, Trustwise, Vijil, Virtue AI. Nothing here was measured against a running product. A measured result on this site looks different: it names a corpus, a split and a rate, the way the benchmark does. This does not.
- Only the vendor’s own words count
- Every documented cell carries the URL of the page it came from and a verbatim quote, listed under Sources below, each one re-checked against the live page. Analyst notes, press coverage and third-party write-ups were not used. A claim with no URL behind it was dropped rather than scored. Research a vendor publishes about an attack is not counted either — explaining a technique is not shipping a control for it, and that rule cost the vendor who contributed several of these techniques the cells it might otherwise have earned.
- What was read, and what was not
- Public HTML only. Gated PDFs, datasheets behind a form and anything requiring a login were not opened, and a few sites serve little text without JavaScript. For the vendors added on 2026-09-27 the read also took in ungated first-party PDFs linked from their sites and, for one, its open-source repositories; each of the four keeps its product documentation behind a login or a password, which was not opened. The two added on 2026-10-01 were read the same way, ungated first-party PDFs included; Above Security’s customer portal is behind a login and was not opened, and Rig Security publishes no product documentation. The eighteen added later on 2026-10-01 were read from the same kinds of first-party material, plus public product documentation, press releases and GitHub repositories, and for Virtue AI, which Fortinet has acquired, Fortinet’s own release; Airia, DeepKeep and HiddenLayer keep some or all of their documentation behind a login or a password, which was not opened, and Virtue AI’s documentation, which is rendered by JavaScript, was read in a browser. So “not described” means not found in the material that was read — narrower than “not published anywhere”, and much narrower than “not built”. That is not a formality, and two measurements on this page show why. A vendor first scored from its product pages alone came out at zero; reading its blog afterwards took it to 4, and one of the deciding posts is absent from its own site’s sitemap. A second vendor went from 13 to 22 the same way. And a sitemap-driven crawl has a systematic blind spot: one vendor’s marketing sitemap lists 481 pages and none of them on its documentation subdomain, which is where nearly all of its quotable claims live. A low count here is as likely to be a gap in the reading as a gap in the product, and it is the vendors whose substance sits off the marketing domain that this method under-reads.
- MoorAI’s score is derived, and the snapshot it came from is named
- MoorAI is not scored from its marketing. Its row is computed during the build from
threats.json— rule base 0.7.0, 77 rules — by matching each rule’s ATLAS mapping against the 76 IDs. A technique counts only when a shipped rule carries that ID or one beneath it, so the number cannot be edited upward; it moves when a rule ships. That file is a copied snapshot of the product repository, not a live feed, so the version above is printed here, and in every build log, on purpose: it has sat a release behind before, and a number whose provenance is invisible rots quietly. The rule base also maps to AML.T0012, which this denominator does not contain. The full rule base is published at the threat catalog. - A count is not a ranking
- Some of these techniques describe the adversary’s own preparation — Reconnaissance, Resource Development and AI Attack Adaptation, by ATLAS’s own tactic definitions: building a proxy model, staging infrastructure, orchestrating an autonomous attack. 27 of the 76 rows are empty for every product in the table, 11 of them preparation; vendors here do document 4 other preparation techniques. Others describe attacks on hosted, internet-reachable agents. A product on a developer’s laptop, one on a SaaS control plane and one at a network egress point are not competing for the same cells. Read the rows, not the totals.
- AML.M0039 AI Honeypots is excluded
- A mitigation rather than an adversary technique. Asking whether a product “covers” it is a category error, so it is left out of the denominator rather than scored against every vendor.
Scroll sideways →
| ATLAS 2026.09 technique | MoorAI | dope.security | Operant AI | Lakera | SentinelOne | Netskope | Forcepoint | Salt Security | BigID | Harmonic Security | Zenity | Cycode | Bifrost Edge | Ent | Endor Labs | Certiv | Backslash Security | Kitecyber | Straiker | MIND | WitnessAI | Lasso Security | Pillar Security | Permiso | Above Security | Rig Security | Noma Security | Onyx Security | Akto | HiddenLayer | Virtue AI | NeuralTrust | DeepKeep | Enkrypt AI | Holistic AI | Airia | Aurascape | Cranium | CyCraft | Levo.ai | PointGuard AI | Singulr AI | Trustwise | Vijil |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AI Model Access | ||||||||||||||||||||||||||||||||||||||||||||
| AI Model Inference API Access AML.T0040 Adversaries may gain access to a model via legitimate access to the inference API.Harmonic Security: Managed endpoints only (Harmonic Endpoint Agent); visibility and per-process/per-user attribution of inference-API connections — this sentence claims detection, not blocking. | ||||||||||||||||||||||||||||||||||||||||||||
| Physical Environment Access AML.T0041 In addition to the attacks that take place purely in the digital domain, adversaries may also exploit the physical environment for their attacks. | ||||||||||||||||||||||||||||||||||||||||||||
| Full AI Model Access AML.T0044 Adversaries may gain full "white-box" access to an AI model. | ||||||||||||||||||||||||||||||||||||||||||||
| AI-Enabled Product or Service AML.T0047 Adversaries may use a product or service that uses artificial intelligence under the hood to gain access to the underlying AI model. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Attack Adaptation | ||||||||||||||||||||||||||||||||||||||||||||
| Create Proxy AI Model — 3 sub-techniques AML.T0005 Adversaries may obtain models to serve as proxies for the target model in use at the victim organization. | ||||||||||||||||||||||||||||||||||||||||||||
| Manipulate AI Model — 4 sub-techniques AML.T0018 Adversaries may manipulate an AI model artifact or its bundled components to change AI system behavior, introduce malicious code, or establish persistent malicious functionality. | ||||||||||||||||||||||||||||||||||||||||||||
| Verify Attack AML.T0042 Adversaries can verify the efficacy of their attack via an inference API or access to an offline copy of the target model. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Prompt Crafting AML.T0065 Adversaries may use their acquired knowledge of the target generative AI system to craft prompts that bypass its defenses and allow malicious instructions to be executed. | ||||||||||||||||||||||||||||||||||||||||||||
| Retrieval Content Crafting AML.T0066 Adversaries may write content designed to be retrieved by user queries and influence a user of the system in some way. | ||||||||||||||||||||||||||||||||||||||||||||
| Autonomous Attack-Path Adaptation AML.T0117 Adversaries may use an AI agent to autonomously construct and repeatedly revise an attack path toward an adversary-defined objective. | ||||||||||||||||||||||||||||||||||||||||||||
| Autonomous AI Agent Communication — 2 sub-techniques AML.T0118 Autonomous AI agents may exchange operational information with other AI agents, sub-agents, or independent agent runs.MoorAI: Requires lineage metadata on agent events.Operant AI: Agent-loop plugin, scoped to Claude Cowork in cloud mode.Lakera: Vendor states it is addressed indirectly, and only where inter-agent interactions are routed through the Guard API; cryptographic/identity controls for inter-agent channels are explicitly left to the customer.Permiso: A forensic trail of the identity and authorisation chain between agents. No detection is described, and the content agents pass to one another is not inspected.Holistic AI: Endlayer's Guardian tier, one of three device-agent tiers; the page gives no mechanism detail for agent-to-agent interception. | ||||||||||||||||||||||||||||||||||||||||||||
| Autonomous Attack Orchestration AML.T0124 Adversaries may use autonomous AI systems as an operational control layer to manage multiple distinct autonomous agents or sub-agents toward a common adversary-defined objective. | ||||||||||||||||||||||||||||||||||||||||||||
| Reconnaissance | ||||||||||||||||||||||||||||||||||||||||||||
| Active Scanning — 4 sub-techniques AML.T0006 Adversaries may actively scan for publicly reachable AI systems and resources for targeting. | ||||||||||||||||||||||||||||||||||||||||||||
| Gather RAG-Indexed Targets AML.T0064 Adversaries may identify data sources used in retrieval augmented generation (RAG) systems for targeting purposes. | ||||||||||||||||||||||||||||||||||||||||||||
| Autonomous Reconnaissance AML.T0116 Adversaries may use autonomous AI agents to conduct Reconnaissance activities. | ||||||||||||||||||||||||||||||||||||||||||||
| Resource Development | ||||||||||||||||||||||||||||||||||||||||||||
| Acquire Public AI Artifacts — 3 sub-techniques AML.T0002 Adversaries may search public sources, including cloud storage, public-facing services, and software or data repositories, to identify AI artifacts. | ||||||||||||||||||||||||||||||||||||||||||||
| Obtain Capabilities — 5 sub-techniques AML.T0016 Adversaries may search for and obtain software capabilities for use in their operations. | ||||||||||||||||||||||||||||||||||||||||||||
| Develop Capabilities — 3 sub-techniques AML.T0017 Adversaries may develop their own capabilities to support operations. | ||||||||||||||||||||||||||||||||||||||||||||
| Publish Hallucinated Entities AML.T0060 Adversaries may create an entity they control, such as a software package, website, or email address corresponding to a source hallucinated by an LLM.MoorAI: Package names only. | ||||||||||||||||||||||||||||||||||||||||||||
| Publish Poisoned AI Artifacts — 3 sub-techniques AML.T0115 Adversaries may create or modify AI artifacts and publish them through public or shared distribution channels to facilitate compromise of downstream AI systems. | ||||||||||||||||||||||||||||||||||||||||||||
| Initial Access | ||||||||||||||||||||||||||||||||||||||||||||
| AI Supply Chain Compromise — 6 sub-techniques AML.T0010 Adversaries may gain initial access to a system by compromising the unique portions of the AI supply chain.SentinelOne: ClawSec is a free open-source skill suite scoped to OpenClaw agents, not the commercial platformNoma Security: A posture assessment of MCP servers (unpinned versions, permissions, low-trust packages, known vulnerabilities), not interception of a compromised package at install or run time.Akto: Stated for agent skills (SKILL.md inventory and scanning) only.Enkrypt AI: A scan with allowlist/denylist recommendations, not a runtime block.PointGuard AI: A rating of the server, weighted 50% security, 30% operational and 20% adoption maturity per PointGuard's own methodology post, not a runtime block.Singulr AI: Drift detection against an approved baseline, described in a post that maps the product onto the LiteLLM compromise after the fact; the rest of that mapping is counterfactual ('would have'). | ||||||||||||||||||||||||||||||||||||||||||||
| Prompt Infiltration via Public-Facing Application AML.T0093 An adversary may introduce malicious prompts into the victim's system via a public-facing application with the intention of it being ingested by an AI at some point in the future and ultimately having a downstream effect.Pillar Security: A posture finding on CI/CD workflow configuration (SAIL 5.3) that flags an agent reachable by public input. It does not detect the injected prompt when it arrives. | ||||||||||||||||||||||||||||||||||||||||||||
| Crafted AI Assistant Links AML.T0131 Adversaries may craft links that open an AI assistant or agent with attacker-controlled input already supplied, so that opening the link initiates an interaction the adversary defines rather than one the target composed. | ||||||||||||||||||||||||||||||||||||||||||||
| Misconfigured or Publicly Exposed AI Services AML.T0132 AI agents and LLM platforms are deployed across diverse architectures, including standalone servers, SaaS platforms, and low-code builders.Lakera: A posture finding surfaced in a risk assessment, not runtime enforcement.Endor Labs: Static, source-and-configuration only — live runtime probes are disabled, so an exposed server is inferred from published source, not observed. Transport and Network Security is one of the three dimensions that contribute findings without a per-dimension score. Blocking depends on an MCP Server Posture policy, which is a guardrail, not a security boundary; enforcement fails open.Noma Security: Posture finding, not runtime enforcement.NeuralTrust: A posture finding from a scan, not runtime enforcement.PointGuard AI: A posture finding on MLOps platforms, not runtime enforcement. | ||||||||||||||||||||||||||||||||||||||||||||
| Execution | ||||||||||||||||||||||||||||||||||||||||||||
| User Execution — 4 sub-techniques AML.T0011 An adversary may rely upon a user to load, execute, interpret, or otherwise use a malicious or unsafe artifact.Certiv: The gate is "the user did not explicitly ask for it", not a malware verdict — Certiv makes no claim to identify a package as malicious, and a dependency the user does request is not checked. Semantic (model-judged) check; action is tunable per enrollment.Lasso Security: Lasso's open-source MCP Gateway security scanner, which gates MCP servers on a reputation score built from marketplace (Smithery, NPM) and GitHub data plus tool-description scanning; it is a reputation threshold, not a malware verdict, and applies only to servers routed through the gateway.HiddenLayer: Credited for the dependency-install clause only; the detection mechanism for malicious packages is not described.Enkrypt AI: Skill Sentinel is a pre-execution scanner run locally or in CI. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Prompt Injection — 3 sub-techniques AML.T0051 An adversary may craft malicious prompts as inputs to an LLM that cause the LLM to act in unintended ways.Bifrost Edge: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.Endor Labs: Source-only: an LLM workflow reads the SKILL.md captured at session start and scores it; skills are never executed and there is no runtime prompt inspection (Endor states it frames security "around the agent's actions, not just its prompts"). Enforcement via a Skill Access policy is a guardrail, not a security boundary, and enforcement fails open.Virtue AI: Red-team testing (AgentSuite-Red), not a runtime prompt-injection control.Enkrypt AI: Enkrypt states its guardrails process inputs of up to 14,000 characters.Holistic AI: Enforced through the HAI Guardian SDK, which the customer integrates into the agent or application so its traffic routes through Holistic's monitoring pipeline.Airia: Traffic routed through the Airia AI Gateway only; Airia's Claude guide says Claude iOS, Android and unlocked Desktop chat cannot be proxied and are monitored after the fact.Cranium: From Arena red teaming, which tests for prompt injection rather than blocking it at runtime.Levo.ai: AI Firewall (inline) product for in-house AI applications; FAQ answer.Trustwise: June 2025 launch press release; the product was then in private preview. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Tool Invocation AML.T0053 Adversaries may use their access to an AI agent to invoke tools the agent has access to.Lakera: SaaS only: the published self-hosted detector list contains neither dangerous-deviation nor the tool allow/deny list.SentinelOne: Described in the future tense as a first phase rather than as shipped behaviour.Netskope: Enforcement on one hosted model platform is documented as failing open, and stdio and SSE transports are listed as untested.Forcepoint: The agent gateway this depends on is documented as pre-general-availability.BigID: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Bifrost Edge: Enforcement is a gateway allow-list; Bifrost states it does not execute the tool call itself.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Straiker: Blocking requires the inline deployment; other deployments are documented as detection only.WitnessAI: An approved-list control: WitnessAI describes it as denying MCP servers and tools that are off the list before they execute, not as judging what an approved tool is asked to do. WitnessAI itself scopes it to “traffic governed through the platform” and, on its home page, to “supported agent workflows”.Permiso: Anomaly detection on tool calls attributed from logs to an identity. The stated response is an identity-layer kill switch once behaviour crosses a threshold. Permiso does not claim to evaluate a call before it runs, and it argues against prevention by guardrails.Rig Security: Inline enforcement on endpoints running the Gatewatch sensor, keyed to which agent is acting and which identity or resource it reaches (Rig's examples are AWS production versus dev). Rig does not publicly describe inspecting prompts, files read or tool arguments for malicious content, and it publishes no product documentation.DeepKeep: Cursor and Claude Code only today; GitHub Copilot, OpenAI Codex, Lovable and Windsurf are planned.Holistic AI: Requires the HAI Guardian SDK in the agent's path; Holistic lists Claude Code among the supported SDKs.Airia: Airia's Claude guide states that agent constraints intercept tool calls at the gateway, and that Bash commands Claude Code runs locally never traverse it.Aurascape: Gateway-routed tool calls only; Aurascape says a call that skips the gateway is caught through the model conversation instead.CyCraft: An OpenClaw plugin only, which sends tool calls to the XecGuard cloud Scan API; no other agent integration is published.Vijil: Library-level enforcement inside agents built with supported frameworks (or wrapped tools); not an interception point for third-party agents. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Clickbait AML.T0100 Adversaries may craft deceptive content designed to bait computer-using AI agents or AI web browsers and tools into taking unintended actions, such as clicking buttons, copying code, or navigating to specific web pages. | ||||||||||||||||||||||||||||||||||||||||||||
| Deploy AI Agent AML.T0103 Adversaries may launch AI agents in the victim's environment to execute actions on their behalf.SentinelOne: framed as shadow-AI hunting, not adversary-deployed-agent detection specificallyNetskope: managed Windows/macOS endpoints only, signature-bound; inventory onlyForcepoint: shadow-AI governance framing; inventory plus console-driven responseStraiker: Discovery/inventory of unknown and shadow agent deployments; containment is a separate product (Agentic Kill Switch).MIND: Inventory and visibility only — shadow-agent discovery, not detection of an adversary launching an agent.WitnessAI: Network-level shadow-AI and shadow-agent discovery; inventory, not detection of an adversary launching an agent.Lasso Security: Shadow-AI and agent discovery with risk scoring; Lasso says a high-risk agent can be blocked, but it is not framed as detection of an adversary deploying an agent.Pillar Security: Stated as a counterfactual about one campaign. The detection is keyed to permission-bypassing launch flags found by configuration scanning, not to the launch of an agent as such.Above Security: Visibility and alerting on OAuth consent grants to third-party AI agents, routed to the security team for an allow-or-revoke decision. Not prevention, and not agents launched on a device. Above says no enforcement action is taken autonomously on an AI verdict.Rig Security: Discovery and attribution of agents on devices where the Gatewatch sensor is deployed. This is inventory, not detection of an adversary launching an agent.Noma Security: Shadow-agent governance of endpoint agents, MCP servers and skills against an approved registry; not framed as detecting an adversary-deployed agent.Akto: Shadow-AI governance against an approved list, not detection of an adversary launching an agent.HiddenLayer: Shadow-AI discovery, not detection of an adversary launching an agent.NeuralTrust: Inventory and discovery rather than enforcement against an adversary-deployed agent.Holistic AI: Inventory and discovery on managed devices rather than enforcement against an adversary-deployed agent; seventeen tools are recognised by name, others surface as unidentified AI processes.Airia: Inventory and discovery rather than detection of an adversary-deployed agent.Aurascape: Shadow-agent discovery, not detection of an adversary launching an agent.PointGuard AI: Inventory on managed endpoints rather than detection of an adversary-deployed agent. | ||||||||||||||||||||||||||||||||||||||||||||
| Persistence | ||||||||||||||||||||||||||||||||||||||||||||
| Training Data Poisoning AML.T0020 Adversaries may manipulate data used for training or fine-tuning an AI model to influence the resulting model's behavior.Netskope: Hedged verb (“help ensure”), stated in an April 2025 press release rather than in product documentation.Salt Security: Monitoring of API payloads directed at training endpoints only; no claim to identify poisoned samples or clean a dataset. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Prompt Self-Replication AML.T0061 An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output.Cranium: A static scan of markdown command and rules files in named directories (.cursor/commands, .windsurf/workflows, .github instructions, agents.md, claude.md, gemini.md), not runtime detection. | ||||||||||||||||||||||||||||||||||||||||||||
| RAG Poisoning AML.T0070 Adversaries may inject malicious content into data indexed by a retrieval augmented generation (RAG) system to contaminate a future thread through RAG-based search results.Levo.ai: Testing of RAG outputs for signs of poisoning, not inspection of what is ingested into the index. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Context Poisoning — 2 sub-techniques AML.T0080 Adversaries may attempt to manipulate the context used by an AI agent's large language model (LLM) to influence the responses it generates or actions it takes.MoorAI: Guidance only — no memory read or diff; memory writes carried in a crafted assistant link only.Lakera: Runtime integration for this is documented as roadmap, and the dangerous-deviation detector as beta.Pillar Security: From red teaming (RedGraph Suite), which probes for memory poisoning rather than enforcing against it at runtime. | ||||||||||||||||||||||||||||||||||||||||||||
| Modify AI Agent Configuration AML.T0081 Adversaries may modify the configuration files for AI agents on a system.MoorAI: Auto-loaded agent-config paths only; proxy and CA-trust overrides only.Operant AI: The claim is detection of writes to agent configuration, not blocking them.SentinelOne: same ClawSec scope; drift detection alerts, does not blockZenity: Configuration-scan coverage is described for Claude Enterprise scopes/hook/skill files; not stated for other agent platforms.Endor Labs: A shipped policy row: it blocks writes to the agent's own settings and hooks, while reads are allowed. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Noma Security: Detection of configuration change as an inventory event; Noma does not say it blocks or attributes the change.Akto: Posture scan of Claude Code, Codex CLI and Copilot CLI config files found by the Endpoint Shield; it flags weakened settings rather than blocking the write.Enkrypt AI: ClawPatrol is an OpenClaw plugin; files are re-hashed every 60 seconds and changed content is sent to the Enkrypt API for a verdict.Cranium: Scans the content of configuration files; it does not watch for or block writes to them. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Tool Data Poisoning AML.T0099 Adversaries may manipulate data in a victim-controlled, trusted, or connected data source that is accessible through an AI agent tool.MoorAI: Detected on read, not at rest in the data source.NeuralTrust: NeuralTrust's model report evaluates its indirect-injection model on an English-only held-out split of its own training corpus, and names browser-agent page injections as the weakest slice. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Tool Poisoning — 3 sub-techniques AML.T0110 Adversaries may poison tools used by AI agents by introducing or modifying malicious content or behavior in a tool's model-visible definition, executable implementation, or runtime responses.MoorAI: Approved-connector allow-list only; tool definition and schema only.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.WitnessAI: From pre-deployment red teaming (Witness Attack), which tests for tool poisoning rather than enforcing against it at runtime.Virtue AI: Static scan of tool descriptions (definition), plus optional code scanning for vulnerabilities; not a runtime check of tool responses.NeuralTrust: A scan of MCP server code and configuration, not runtime enforcement.Enkrypt AI: Inline only where MCP traffic is routed through the gateway.Airia: Airia states Tool Scanning is informational, not a gate: it flags suspicious tool definitions and does not block them.Aurascape: Bounded by Aurascape itself to governed deployments.CyCraft: Content scan of skill text submitted to the API; CyCraft's FAQ says XecGuard is not recommended for scanning large documents or full-length files.Levo.ai: Pre-deployment security testing of MCP servers, not runtime prevention; covers poisoned tool output (runtime response), not poisoned tool definitions.Trustwise: Given as an example of the Prompt Shield; covers instructions hidden in a tool description (definition), not compromised tool implementations or runtime responses. | ||||||||||||||||||||||||||||||||||||||||||||
| Defense Evasion | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Jailbreak AML.T0054 Adversaries may induce a large language model (LLM) to ignore, circumvent, or override its safety/alignment behaviors and/or guardrails to elicit outputs the model is intended to withhold.Zenity: Hedged verb ("helps protect against"); stated on the Microsoft 365 Copilot page. Corroborated on the Claude Enterprise page, where AIDR's real-time coverage list names "jailbreaks".Bifrost Edge: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.Noma Security: From AI Red Teaming, which tests the customer's own apps and agents for jailbreaks rather than blocking them at runtime.Onyx Security: Automated red teaming of deployed agents (testing). The runtime jailbreak claim on the platform page shares a sentence with the prompt-injection cell and is not counted twice.HiddenLayer: From AI Attack Simulation, which tests for jailbreaks rather than blocking them at runtime.NeuralTrust: Enforced where traffic reaches a NeuralTrust collector (gateway, SDK, browser, sidecar or log stream).DeepKeep: DeepKeep's own blog says you can't reliably detect every jailbreak and recommends containment over detection.Aurascape: Applied on the model-conversation channel through the AI Proxy. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Trusted Output Components Manipulation — 1 sub-technique AML.T0067 Adversaries may utilize prompts to a large language model (LLM) which manipulate various components of its response in order to make it appear trustworthy to the user.MoorAI: Links only — a link whose visible address differs from where it goes. Other output components are not checked. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Prompt Obfuscation AML.T0068 Adversaries may hide or otherwise obfuscate prompt injections or retrieval content to avoid detection from humans, large language model (LLM) guardrails, or other detection mechanisms.MoorAI: Text and markup only. Low-contrast text rendered inside a raster image is not detected.Akto: Stated for the Claude Code UserPromptSubmit hook, i.e. the user's prompt, not tool output.NeuralTrust: NeuralTrust's own model report names inline-encoded payloads (base64/hex/ROT13) as the toxicity model's one material robustness gap.Cranium: Static scan of the same agent configuration files for zero-width, bidi, variation-selector and tag characters. | ||||||||||||||||||||||||||||||||||||||||||||
| False RAG Entry Injection AML.T0071 Adversaries may introduce false entries into a victim's retrieval augmented generation (RAG) database. | ||||||||||||||||||||||||||||||||||||||||||||
| Corrupt AI Model AML.T0076 An adversary may purposefully corrupt a malicious AI model file so that it cannot be successfully deserialized in order to evade detection by a model scanner. | ||||||||||||||||||||||||||||||||||||||||||||
| Manipulate User LLM Chat History AML.T0092 Adversaries may manipulate a user's large language model (LLM) chat history to cover the tracks of their malicious behavior.MoorAI: Local agent transcript files only. Chat history held on a provider's servers is not visible from an endpoint and is not claimed. | ||||||||||||||||||||||||||||||||||||||||||||
| Delay Execution of LLM Instructions AML.T0094 Adversaries may include instructions to be followed by the AI system in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass controls placed on the AI system. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Supply Chain Rug Pull AML.T0109 Adversaries may publish legitimate AI components or software, gain user adoption, then push an update with a malicious variant, leading to AI Supply Chain Compromise.Endor Labs: Re-scoring on change is the defence, but the rug-pull behaviour itself is never described. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Straiker: From red-team testing, which probes for this rather than enforcing against it at runtime.Enkrypt AI: ClawPatrol, an OpenClaw plugin; a modified skill is re-scanned and alerted on, not blocked.Airia: Applies to tools served through an Airia MCP Gateway or Deployment. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Supply Chain Reputation Inflation AML.T0111 AI Supply Chain Reputation Inflation is the process of building or leveraging genuinely credible-looking trust signals to increase the perceived legitimacy of AI supply chain components, with the goal of driving adoption of malicious or… | ||||||||||||||||||||||||||||||||||||||||||||
| Triggers in Multimodal Inputs AML.T0129 Adversaries may place instructions or triggers in one part of a multimodal input to influence the model while staying unnoticed by human reviewers and by defenses that do not inspect all input modalities.MoorAI: The file-metadata channel only — EXIF and equivalents. Audio and video tracks are not inspected.WitnessAI: From pre-deployment red teaming (Witness Attack), which probes with multimodal attacks rather than inspecting multimodal inputs at runtime; no runtime multimodal inspection is claimed.Enkrypt AI: From red teaming, which probes for this rather than enforcing against it at runtime. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Targeted Cloaking AML.T0134 Adversaries may selectively deliver malicious or manipulated content to AI systems, while presenting different benign content to human users, web crawlers, or security detection mechanisms.MoorAI: Only the artefact the cloaked response leaves behind. The server-side User-Agent branch is invisible from an endpoint and is not claimed. | ||||||||||||||||||||||||||||||||||||||||||||
| Discovery | ||||||||||||||||||||||||||||||||||||||||||||
| Discover AI Artifacts AML.T0007 Adversaries may search private sources to identify AI learning artifacts that exist on the system and gather information about them.Operant AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.SentinelOne: inventory/posture only; the /platform/ai-security-posture-management page is a live 404, so blog announcement is the only sourceBigID: Inventory-only: detects model files/binaries at rest; no claim to detect an adversary enumerating them.Pillar Security: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Permiso: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Noma Security: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.HiddenLayer: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Holistic AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Cranium: Inventory from repository scanning, not detection of an adversary enumerating artefacts.PointGuard AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover AI Model Family AML.T0014 Adversaries may discover the general family of a model. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover LLM Hallucinations AML.T0062 Adversaries may prompt large language models and identify hallucinated entities.Lakera: From red teaming, which probes for this rather than enforcing against it at runtime. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover AI Model Outputs AML.T0063 Adversaries may discover model outputs, such as class scores, whose presence is not required for the system to function and are not intended for use by the end user. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover LLM System Information — 3 sub-techniques AML.T0069 The adversary is trying to discover something about the large language model's (LLM) system information. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover AI Agent Configuration — 4 sub-techniques AML.T0084 Adversaries may attempt to discover configuration information for AI agents present on the victim's system.Operant AI: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.Lakera: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.SentinelOne: OneClaw is a standalone discovery/observability tool; inventory only, no enforcementEndor Labs: Inventory/visibility only. The system policy that guards agent configuration blocks writes, edits and deletes but explicitly allows reads, so discovery of the configuration itself is not blocked. Guardrails, not a security boundary; enforcement fails open.Kitecyber: Inventory of agent configuration and loaded skills; not runtime enforcement.Lasso Security: Inventory of the defender's own agents (read-only CI and cloud-platform integrations), not detection of an adversary enumerating agent configuration.Pillar Security: An inventory of each agent's configuration. It does not detect an adversary who is enumerating that configuration.Permiso: An inventory of which tools and data each agent can reach. It does not detect an adversary who is enumerating agent configuration.Noma Security: Inventory built from EDR or MDM telemetry; it does not detect an adversary enumerating agent configuration.Akto: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.NeuralTrust: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.DeepKeep: A design-time assessment of the customer's own agent, not runtime enforcement.Enkrypt AI: A pre-deployment and periodic scan of MCP servers, not runtime enforcement.Airia: Observe mode of the airiad endpoint agent; Airia's guide lists macOS Apple Silicon as the packaged platform today.Cranium: Repository scan of six agent frameworks (Strands, CrewAI, smolagents, AutoGen-AgentChat, LangGraph, OpenAI Agents); inventory only. | ||||||||||||||||||||||||||||||||||||||||||||
| Discover AI Agent Runtime Capabilities AML.T0133 Adversaries may interact with an AI agent at runtime to reveal the capabilities available to it, without requiring access to its underlying configuration.Lakera: From red teaming, which probes for this rather than enforcing against it at runtime.Pillar Security: From red teaming, which performs the capability discovery itself rather than enforcing against it at runtime.Noma Security: Inventory of the defender's own MCP servers and tools, not detection of an agent being probed for its capabilities.Akto: Inventory of the defender's own agents' reach, not detection of capability probing.Aurascape: Inventory of the defender's MCP servers and tools. | ||||||||||||||||||||||||||||||||||||||||||||
| Collection | ||||||||||||||||||||||||||||||||||||||||||||
| AI Artifact Collection AML.T0035 Adversaries may collect AI artifacts for Exfiltration or for use in AI Attack Staging.MoorAI: Model files and caches moved by a single command. Collection spread across several steps is not claimed. | ||||||||||||||||||||||||||||||||||||||||||||
| Data from AI Services — 2 sub-techniques AML.T0085 Adversaries may use their access to a victim organization's AI-enabled services to collect proprietary or otherwise sensitive information.Netskope: the collection-side claim rests on 'tool call results' and 'resource content'; the trailing clause is egress-framedKitecyber: Endpoint-local detection/alerting on agent access to sensitive data; no RAG-database coverage.MIND: Visibility of what data agents reach, from the data side (endpoint agent, browser extension, SaaS connectors); no claim to inspect RAG retrievals or agent tool results.Permiso: Keyed to first-time data access against the agent's own baseline, and answered at the identity layer. Permiso does not inspect what is retrieved. | ||||||||||||||||||||||||||||||||||||||||||||
| Exfiltration | ||||||||||||||||||||||||||||||||||||||||||||
| Exfiltration via AI Inference API — 3 sub-techniques AML.T0024 Adversaries may exfiltrate private information via AI Model Inference API Access.Levo.ai: Names model extraction only (AML.T0024.002); no claim for membership inference or model inversion. | ||||||||||||||||||||||||||||||||||||||||||||
| Extract LLM System Prompt AML.T0056 Adversaries may attempt to extract a large language model's (LLM) system prompt.Netskope: AI Red Teaming probe set - pre-deployment testing, not runtime enforcementAkto: A listed catch of the PromptInjection guardrail rather than a separate detector.HiddenLayer: System prompt hardening in attack simulation; a test, not runtime prevention.NeuralTrust: A detection rate on NeuralTrust's own benchmark, which the report says was built to its own taxonomies and carries a home-field advantage.Airia: From red teaming, which probes for this rather than enforcing against it at runtime. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Data Leakage AML.T0057 Adversaries may craft prompts that induce the LLM to leak sensitive information.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Virtue AI: Fortinet's description of Virtue AI's real-time guardrails in its acquisition release; the jailbreak claim in this sentence is not counted again.Cranium: From Arena red teaming, which simulates data leakage rather than preventing it at runtime.CyCraft: CyCraft's FAQ says the PII Policy detects personal-information attributes broadly at a low risk level and 'is not designed as a malicious activity detection alert'. | ||||||||||||||||||||||||||||||||||||||||||||
| LLM Response Rendering AML.T0077 Adversaries may induce a large language model (LLM) to respond with private information structured in a reference to external content that, when rendered by the user's client, makes a request to an adversary-controlled server, exfiltrati…MoorAI: The rendered-URL channel. There is no OCR on egress, so an image-borne payload is not read.HiddenLayer: A URL detection outcome in Agentic Runtime Security; HiddenLayer does not say it checks whether the link carries conversation data. | ||||||||||||||||||||||||||||||||||||||||||||
| Exfiltration via AI Agent Tool Invocation AML.T0086 AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary.MoorAI: Send-message tool families only; known local secret values only.dope.security: Egress data-loss control over what an agent uploads or pastes, not interception of the tool call itself. dope states it does not claim MCP security.Operant AI: Response enforcement is documented as detect-and-log for this path rather than blocking.Lakera: Dangerous Deviation detector is in beta, ships in a conservative configuration, and is recommended in Detect mode before Enforce.BigID: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Endor Labs: The name of a shipped system policy rather than a described capability. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.MIND: Egress data-loss control at the endpoint, browser and SaaS layer; MIND nowhere claims to intercept or evaluate an agent tool call itself.Above Security: After-the-fact investigation and attribution of data that an OAuth-scoped third-party agent has already reproduced off-site. Above does not claim to intercept or evaluate the agent's tool calls.Onyx Security: An anonymised scenario the post says is composited from POV work with several customers (a coding agent posting an AWS key to an external webhook after an injected README instruction).Akto: A host and path blocklist with wildcards; it does not inspect what the request carries.NeuralTrust: Stated as identification within agent tracing; the sentence does not say the exfiltrating call is blocked.Levo.ai: General agent-enforcement claim; does not name a specific tool-invocation exfiltration mechanism. | ||||||||||||||||||||||||||||||||||||||||||||
| Impact | ||||||||||||||||||||||||||||||||||||||||||||
| Denial of AI Service AML.T0029 Adversaries may target AI-enabled systems with a flood of requests for the purpose of degrading or shutting down the service.Akto: A use case of the Behavioural Anomaly guardrail (request-rate and repetition baselines), not a dedicated denial-of-service control.HiddenLayer: A per-requester token threshold (default 4096 tokens).Vijil: A Diamond evaluation probe (pre-deployment testing), not a runtime control. | ||||||||||||||||||||||||||||||||||||||||||||
| Erode AI Model Integrity AML.T0031 Adversaries may degrade the target model's performance with adversarial data inputs to erode confidence in the system over time. | ||||||||||||||||||||||||||||||||||||||||||||
| Cost Harvesting — 3 sub-techniques AML.T0034 Adversaries may deliberately drive a victim's AI services beyond normal operating capacity with the intent of increasing the cost of services.Netskope: framed as spend/budget control, not abuse or attack detection; release-note summary lineCertiv: Certiv states this capability is in public preview.WitnessAI: Framed as AI FinOps spend control — blocking or rerouting prompts classified as non-productive — rather than detection of deliberate cost harvesting.Holistic AI: Framed as cost control; Holistic states its cost figures are estimates from observed token counts against published pricing.PointGuard AI: Framed as runaway-loop and drift detection, not as an adversary driving up cost.Trustwise: Framed as cost optimisation of runaway agent loops rather than defence against an adversary inflating cost. | ||||||||||||||||||||||||||||||||||||||||||||
| Spamming AI System with Chaff Data AML.T0046 Adversaries may spam the AI system with chaff data that causes increase in the number of detections. | ||||||||||||||||||||||||||||||||||||||||||||
| External Harms — 5 sub-techniques AML.T0048 Adversaries may abuse their access to a victim system and use its resources or capabilities to further their goals by causing harms external to that system.Permiso: Covers LLMjacking only, meaning unauthorised use of the customer's own hosted LLM instances. ATLAS's LLM Jacking case study (AML.CS0030) maps that to the financial-harm sub-technique. Harmful-content output is not addressed.Akto: Framed as protecting the customer's LLM licence standing rather than as stopping misuse by an adversary. | ||||||||||||||||||||||||||||||||||||||||||||
| Erode Dataset Integrity AML.T0059 Adversaries may poison or manipulate portions of a dataset to reduce its usefulness, reduce trust, and cause users to waste resources correcting errors. | ||||||||||||||||||||||||||||||||||||||||||||
| Data Destruction via AI Agent Tool Invocation AML.T0101 Adversaries may invoke an AI agent's tool capable of performing mutative operations to perform Data Destruction.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Onyx Security: Policy-based blocking of destructive tool calls, framed by Onyx around agent mistakes rather than adversary-driven destruction.DeepKeep: Sends the command for developer approval rather than blocking it outright; Cursor and Claude Code only today.Aurascape: Caught in the tool call the model streams back over the network, before the client executes it, so it depends on traffic being steered through Aurascape. | ||||||||||||||||||||||||||||||||||||||||||||
| Machine Compromise — 2 sub-techniques AML.T0112 Adversaries may compromise a machine by exploiting or manipulating AI-enabled components on the system.MoorAI: Reverse-shell / remote-exec payloads only. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Response Biasing AML.T0130 Adversaries may manipulate an AI assistant so that it favors adversary-chosen sources, or content in its responses. | ||||||||||||||||||||||||||||||||||||||||||||
| Credential Access | ||||||||||||||||||||||||||||||||||||||||||||
| RAG Credential Harvesting AML.T0082 Adversaries may attempt to use their access to a large language model (LLM) on the victim's system to collect credentials.Lakera: From red teaming, which probes rather than enforces, and names credentials in system prompts and configuration rather than a retrieval corpus. | ||||||||||||||||||||||||||||||||||||||||||||
| Credentials from AI Agent Configuration AML.T0083 Adversaries may access the credentials of other tools or services on a system from the configuration of an AI agent.dope.security: Visibility of the MCP server domains a device reaches, which dope itself calls a first step toward an inventory rather than a control. dope states elsewhere that it does not claim MCP security; this cell is credited because the claim is egress visibility and its source post post-dates that statement.Operant AI: An inventory of which credentials each integration uses, rather than prevention of credential retrieval.Lakera: A posture finding surfaced in a risk assessment, not runtime prevention of credential retrieval.Salt Security: Posture-scan detection of exposed credentials across agentic components (the section's own bullets name "Hardcoded tokens and credentials" and "Risky MCP configurations"); inventory/flagging, not runtime prevention of credential read.Endor Labs: A scoring dimension rather than an enforced block. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Backslash Security: Free standalone Claw-Hunter script for OpenClaw only; read-only scan of the agent install/config, not platform-wide enforcement.Pillar Security: A configuration-posture finding about credentials stored in MCP configuration. It does not prevent an adversary reading them at runtime.Noma Security: A posture finding about secrets stored in agent instructions; it does not describe preventing an agent from reading them.Onyx Security: Posture scanning of agent configuration files for stored credentials, from a list of what Onyx's configuration reviews look for; it reduces what an adversary could harvest rather than detecting the harvesting.Akto: A risk-scoring finding about credentials stored in skill files, not prevention of an agent reading them.PointGuard AI: Removes standing credentials from agent configuration rather than detecting their theft. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent Tool Credential Harvesting AML.T0098 Adversaries may attempt to use their access to an AI agent on the victim's system to retrieve data from available agent tools to collect credentials.MoorAI: Local credential files and keychain only.Netskope: wording is 'manipulating' (create/rotate/export/delete), broader than harvestingForcepoint: AI Agent Gateway is stated on the same page as 'currently in early access ahead of general availability'; inline app support only 'spans core enterprise SaaS platforms at launch'Cycode: IDE-boundary control framed as data-leak prevention rather than adversary detection; enforced where Cycode AI Guardrails hooks are installed.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Lasso Security: The open-source gateway's basic plugin masks the token types it lists (cloud, GitHub, GitLab, Hugging Face, JWT, Slack and similar) in MCP tool responses routed through the gateway; pattern masking, not detection of harvesting intent.Pillar Security: A behavioural-baseline alert on rapid, sequential reads of credential files, which Pillar describes as a deviation that triggers an alert. A single credential read by an agent is not claimed.Noma Security: Stated in a December 2025 launch post about Cursor hooks; the Claude Code coverage page does not repeat the file-access claim.Akto: Output-side scan of what a tool returns; the documented example is an API key in a file-reader response.DeepKeep: AI Lens for Developers supports Cursor and Claude Code today; other coding agents are planned.PointGuard AI: Managed macOS, Windows and Linux endpoints running PointGuard's endpoint client. | ||||||||||||||||||||||||||||||||||||||||||||
| Command and Control | ||||||||||||||||||||||||||||||||||||||||||||
| AI Service API AML.T0096 Adversaries may communicate using the API of an AI service on the victim's system. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Agent AML.T0108 Adversaries may abuse AI agents present on the victim's system for command and control.Zenity: Named as an AIDR detection class on the Claude Enterprise page only; no mechanism detail beyond the named detection. | ||||||||||||||||||||||||||||||||||||||||||||
| AI Artifact Repository AML.T0120 Adversaries may repurpose AI artifact repositories as asynchronous command-and-control channels. | ||||||||||||||||||||||||||||||||||||||||||||
| Covered, of 76 | 31 | 2 | 23 | 21 | 15 | 17 | 9 | 12 | 8 | 3 | 23 | 10 | 7 | 0 | 18 | 14 | 14 | 4 | 22 | 4 | 14 | 23 | 26 | 9 | 2 | 2 | 20 | 7 | 21 | 14 | 6 | 19 | 9 | 20 | 12 | 12 | 11 | 10 | 8 | 11 | 19 | 4 | 6 | 6 |
Sources — every documented cell, with the words behind it
MoorAI derived from rule base 0.7.0
MoorAI’s row is not a reading of MoorAI’s own marketing. It is computed during the site build from src/_data/threats.json — rule base 0.7.0, 77 rules, carrying 33 distinct ATLAS ids — by matching each rule’s mapping against the 76 IDs above. That file is a copied snapshot of the product repository rather than a live feed, so the version is named here and printed in every build log. 16 of the cells below are bounded: real coverage with an edge, and the edge is written out. The same rule base is published in full at the threat catalog.
AML.T0118— Sub-agent / A2A delegation
Limit: Requires lineage metadata on agent events.AML.T0060— Hallucinated or typosquatted dependency
Limit: Package names only.AML.T0010— Shadow AI; Unsanctioned or malicious package installAML.T0131— Crafted AI assistant linkAML.T0011— Dangerous links, files, or scripts from AI output; AI-Assisted Malware - dangerous code, macros, and scripts; Insecure code generation; Unsafe AI model loadingAML.T0051— Direct Prompt Injection; Indirect Prompt Injection; Second-Order Prompt Injection; Model-escalated risk (on-device second opinion); AI rules/config file poisoningAML.T0053— Downloading malicious Skills, Plugins, or Extensions; Plugins with excessive permissions; Information exposure due to excessive permissions; Automatic action taken on the employee's behalf; Excessive Agency; Tool Misuse; AI browser extensions with browser access; Agent entitlement drift (out-of-scope action); Sub-agent / A2A delegationAML.T0020— Knowledge-base poisoning / RAG PoisoningAML.T0061— Self-replicating promptAML.T0080— Memory Poisoning; Crafted AI assistant link
Limit: Guidance only — no memory read or diff; memory writes carried in a crafted assistant link only.AML.T0081— AI rules/config file poisoning; Transit interception (proxy / CA environment injection)
Limit: Auto-loaded agent-config paths only; proxy and CA-trust overrides only.AML.T0099— Second-Order Prompt Injection
Limit: Detected on read, not at rest in the data source.AML.T0110— MCP / Connector Tool Poisoning; AI rules/config file poisoning
Limit: Approved-connector allow-list only; tool definition and schema only.AML.T0054— Direct Prompt Injection; Indirect Prompt InjectionAML.T0067— Deceptive link in AI output
Limit: Links only — a link whose visible address differs from where it goes. Other output components are not checked.AML.T0068— Indirect Prompt Injection; Invisible or obfuscated text in content
Limit: Text and markup only. Low-contrast text rendered inside a raster image is not detected.AML.T0092— Agent chat-history tampering
Limit: Local agent transcript files only. Chat history held on a provider's servers is not visible from an endpoint and is not claimed.AML.T0129— Instructions in file metadata
Limit: The file-metadata channel only — EXIF and equivalents. Audio and video tracks are not inspected.AML.T0134— Content aimed only at the AI client
Limit: Only the artefact the cloaked response leaves behind. The server-side User-Agent branch is invisible from an endpoint and is not claimed.AML.T0133— Agent capability enumerationAML.T0035— AI model or dataset collection
Limit: Model files and caches moved by a single command. Collection spread across several steps is not claimed.AML.T0024— Unapproved model endpoint (rogue LLM egress); Transit interception (proxy / CA environment injection); Local secret value egressAML.T0056— System-prompt extraction attempt; System-prompt or instruction leakage in outputAML.T0057— Sensitive data leak; Intellectual-property exposure; Employee or customer privacy violation; Sensitive data retained in an AI conversation; AI Meeting Assistants and transcription of sensitive meetings; Leakage via email and Teams/Slack thread summaries; Leakage via conversation history and uploaded files; Data Residency - processing in an unapproved country; Cross-Context Leakage; Unauthorized AI Sharing - sharing output with excess information; Secret / credential exposure; Protected health information (HIPAA / PHI); Lethal trifecta exposureAML.T0077— Exfiltration through rendered output
Limit: The rendered-URL channel. There is no OCR on egress, so an image-borne payload is not read.AML.T0086— Sending external email or notifications; Local secret value egress
Limit: Send-message tool families only; known local secret values only.AML.T0034— AI Cost Abuse; Oversized or runaway inputAML.T0048— Reliance on incorrect answers or hallucinations; AI-enhanced phishing; BEC, Business Email Compromise; Deepfake voice or video; AI-based Vishing and Smishing; Bias and discrimination in outputs; Fake links and sources generated by AI; AI-Generated Invoices; Synthetic Identity of suppliers or candidates; Misleading Translation; Overconfidence in an AI answer; Legal / contract language; Employee relations / PIP; Copyright / license contamination; Changing security settings, IAM, or firewall; Sending external email or notifications; Creating users, tokens, or API keys; Deploying to a production environmentAML.T0101— Destructive command execution; Destructive tool / MCP callAML.T0112— Reverse shell / remote code execution
Limit: Reverse-shell / remote-exec payloads only.AML.T0098— Credential / secret-file access
Limit: Local credential files and keychain only.
dope.security 2 of 76
dope publishes explicit boundaries and they are honoured here over its own earlier marketing. On 31 August 2026 it wrote that it does not govern agent runtimes on Bedrock or Vertex and “does not claim MCP security”, assigning MCP server governance to a named competitor, and it separately assigns prompt injection and model security to others. Two cells credited from earlier posts were removed on the strength of that. The two that remain are egress visibility and egress data-loss control — what dope still claims — and one of them comes from a post published after the disclaimer.
AML.T0086—If an agent uploads a file or pastes content containing PII, PCI, PHI, or source code, dope.security can block, warn, or log based on your policy
https://dope.security/post/ai-browser-governance-2026 (read 2026-09-20)
Limit: Egress data-loss control over what an agent uploads or pastes, not interception of the tool call itself. dope states it does not claim MCP security.AML.T0083—dope.security surfaces every MCP server domain a device connects to, which is the first step to inventorying those identities.
https://dope.security/post/non-human-identity-security-2026 (read 2026-09-20)
Limit: Visibility of the MCP server domains a device reaches, which dope itself calls a first step toward an inventory rather than a control. dope states elsewhere that it does not claim MCP security; this cell is credited because the claim is egress visibility and its source post post-dates that statement.
Operant AI 23 of 76
Most of these cells come from Operant's engineering blog rather than its product pages. Operant also asserts coverage on an OWASP comparison page using Detects and Defends badges beside OWASP's own copied risk definitions — real assertions by the vendor, but with no sentence to quote, so this method cannot count them. Searched for and not found anywhere in its material: system-prompt extraction, RAG poisoning and hallucinated-package publication. Its documentation site requires a login and was not read.
AML.T0118—Sub-agent delegation — when the primary agent spawns a child, the child's loop is traced under the same policy and session identity.
https://www.operant.ai/art-kubed/expanding-operants-claude-coverage (read 2026-09-20)
Limit: Agent-loop plugin, scoped to Claude Cowork in cloud mode.AML.T0010—packages pulled dynamically by Node and Python executables are intercepted and inspected before they are allowed to execute
https://www.operant.ai/art-kubed/shai-hulud-returns-for-the-agents-how-operant-blocks-the-keyv-cacheable-npm-worm-at-scan-time-and-at-runtime (read 2026-09-20)AML.T0011—blocking malicious payloads, prompt-injected commands, and unsanctioned package installs before they run
https://www.operant.ai/platform/endpoint-protector (read 2026-09-20)AML.T0051—Gatekeeper, sitting inline, catches the injection pattern semantically
https://www.operant.ai/art-kubed/securing-your-databricks-data-beyond-the-lakehouse-with-operants-ai-defense-platform (read 2026-09-20)AML.T0053—Enforce least privilege execution controls and detailed access permissions for MCP tool usage.
https://www.operant.ai/solutions/mcp-gateway (read 2026-09-20)AML.T0080—Secure multi-agent handoffs and prevent memory poisoning that can turn compromised interactions into full-scale breaches.
https://www.operant.ai/platform/agent-protector (read 2026-09-20)AML.T0081—Operant monitors writes to .claude/settings.json, .claude/settings.local.json, .mcp.json, and .vscode/tasks.json.
https://www.operant.ai/art-kubed/shai-hulud-returns-for-the-agents-how-operant-blocks-the-keyv-cacheable-npm-worm-at-scan-time-and-at-runtime (read 2026-09-20)
Limit: The claim is detection of writes to agent configuration, not blocking them.AML.T0099—Perform context-aware analysis of all data passed through MCP to detect tampering or malicious content
https://www.operant.ai/solutions/mcp-gateway (read 2026-09-20)AML.T0110—Prompt injections, jailbreaks, tool poisoning attempts, and unauthorized access patterns are detected and blocked inline, before they execute.
https://www.operant.ai/art-kubed/observability-is-not-security-you-need-both-heres-how-to-pair-operant-mcp-gateway-with-datadogs-mcp-server (read 2026-09-20)AML.T0054—Runtime detection of overprivileged access via prompt injections or jailbreaks.
https://www.operant.ai/platform/3d-runtime-defense (read 2026-09-20)AML.T0109—A release that changes no library code but adds an executable preinstall entrypoint is, by itself, a high-severity structural anomaly.
https://www.operant.ai/art-kubed/shai-hulud-returns-for-the-agents-how-operant-blocks-the-keyv-cacheable-npm-worm-at-scan-time-and-at-runtime (read 2026-09-20)AML.T0007—live discovery of every AI workload, model, API, and agent, regardless of where they are deployed
https://www.operant.ai/platform/ai-gatekeeper (read 2026-09-20)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0084—Build a live inventory of every AI tool, model, MCP server, and skill in active use across your workforce.
https://www.operant.ai/platform/endpoint-protector (read 2026-09-20)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.AML.T0085—Stops bulk reads and credential access before execution
https://www.operant.ai/platform/semantic-firewall (read 2026-09-20)AML.T0024—Detect and prioritize AI-specific risks like prompt injection, LLM poisoning, model theft, and sensitive data leakage.
https://www.operant.ai/solutions/ai-security (read 2026-09-20)AML.T0057—real-time detection and mitigation of AI-native threats such as prompt injections, jailbreaks, model extraction, and data exfiltration through output leakage
https://www.operant.ai/art-kubed/securing-data-in-use-in-the-age-of-ai (read 2026-09-20)AML.T0086—correlates behavioral drift, detecting when a tool is being repurposed for data exfiltration rather than normal automation.
https://www.operant.ai/art-kubed/shadow-escape (read 2026-09-20)
Limit: Response enforcement is documented as detect-and-log for this path rather than blocking.AML.T0029—prevents token floods and throttles risky behavior.
https://www.operant.ai/art-kubed/anti-virus-for-mcp-part2 (read 2026-09-20)AML.T0034—Token Meter tracks token use live and applies limits before the spend is locked in.
https://www.operant.ai/solutions/token-meter (read 2026-09-20)AML.T0101—Checked for signs of data theft, destructive actions, and reverse shells before they run
https://www.operant.ai/solutions/claude-coverage (read 2026-09-20)AML.T0112—a new capability for Agent Protector that detects and blocks malicious code before it is executed by endpoint AI agents
https://www.operant.ai/art-kubed/introducing-operant-codeinjectionguard-for-ai-agents (read 2026-09-20)AML.T0083—Let Operant list every Claude surface, MCP connection, skill, plugin, and agent in use, plus the credentials each built-in integration uses
https://www.operant.ai/solutions/claude-coverage (read 2026-09-20)
Limit: An inventory of which credentials each integration uses, rather than prevention of credential retrieval.AML.T0098—CodeInjectionGuard distinguishes legitimate developer tooling from credential harvesting, persistence installation, and lateral movement attempts.
https://www.operant.ai/art-kubed/introducing-operant-codeinjectionguard-for-ai-agents (read 2026-09-20)
Lakera 21 of 76 · partial review
This vendor had a shallower read than the others here, for a reason recorded below. Its count is a floor rather than a comparable figure, and on this page a shallower read has repeatedly meant a lower count rather than a weaker product. It is marked rather than quietly counted.
Lakera Guard is now published under Check Point, and nearly all of its quotable claims sit on its documentation site rather than its marketing site. Its blog and security guides were deliberately not read, which is the largest unread surface of any vendor here, so this count is a floor. Two candidate cells were dropped because the wording described how the attack works rather than what the product does. Lakera's own ATLAS mapping exists inside the product but is not published, so nothing was scored from it.
AML.T0118—Inter-agent communication (ASI07) is addressed indirectly: by inspecting the content agents pass between each other when those interactions are screened through the Guard API.
https://docs.lakera.ai/docs/agent-security/framework-mapping (read 2026-09-20)
Limit: Vendor states it is addressed indirectly, and only where inter-agent interactions are routed through the Guard API; cryptographic/identity controls for inter-agent channels are explicitly left to the customer.AML.T0010—Examples: unofficial or unverified MCP servers, MCP servers whose public code shows vulnerabilities or suspicious indicators, and components of unknown origin.
https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)AML.T0132—Examples: an agent owned by a non-organizational identity, and weak or missing authentication configuration on platforms that expose it.
https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)
Limit: A posture finding surfaced in a risk assessment, not runtime enforcement.AML.T0011—Prevent attackers manipulating the LLM into displaying malicious or phishing links to your users by detecting unknown links.
https://docs.lakera.ai/docs/defenses (read 2026-09-20)AML.T0051—Check Point AI Guardrails provides prompt defenses through detecting prompt attacks in real-time
https://docs.lakera.ai/docs/prompt-defense (read 2026-09-20)AML.T0053—The Tool Allow/Deny List enforces which tools an agent may call at runtime, at the moment of tool invocation
https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
Limit: SaaS only: the published self-hosted detector list contains neither dangerous-deviation nor the tool allow/deny list.AML.T0070—For static document sets like knowledge bases, screen documents for prompt attack poisoning off-line
https://docs.lakera.ai/docs/api/guard (read 2026-09-20)AML.T0080—Tool messages are screened as untrusted content, so Prompt Defense and Data Leakage detection run on them according to your policy.
https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
Limit: Runtime integration for this is documented as roadmap, and the dangerous-deviation detector as beta.AML.T0099—Screens the content a tool returns before the agent consumes it.
https://docs.lakera.ai/docs/api/screening-roles (read 2026-09-20)AML.T0110—screen tool descriptions as content when a new tool or MCP server is added
https://docs.lakera.ai/docs/prompt-defense (read 2026-09-20)AML.T0054—This includes jailbreaks, prompt injections and any attempts to manipulate and exploit AI models through malicious or unintentionally troublesome instructions
https://docs.lakera.ai/docs/defenses (read 2026-09-20)AML.T0068—Catch instruction overrides, jailbreaks, indirect injections, and obfuscated prompts as they happen, before they reach your model.
https://www.lakera.ai/risk/prompt-injection-attacks (read 2026-09-20)AML.T0062—Inducing the model to fabricate facts, citations, entities, or statistics presented as real
https://docs.lakera.ai/docs/red/attack-coverage (read 2026-09-20)
Limit: From red teaming, which probes for this rather than enforcing against it at runtime.AML.T0084—Discovery connects to the platforms where agents run and builds an inventory.
https://docs.lakera.ai/docs/agent-security/discovery (read 2026-09-20)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.AML.T0133—Extraction of information about available tools, functions, APIs, or capabilities that the system has access to
https://docs.lakera.ai/docs/red/attack-coverage (read 2026-09-20)
Limit: From red teaming, which probes for this rather than enforcing against it at runtime.AML.T0056—In order to prevent extraction of system prompts, particular for further exploitation by attackers, custom data leakage guardrails can be setup within AI Guardrails
https://docs.lakera.ai/docs/data-leakage-prevention (read 2026-09-20)AML.T0057—Check Point AI Guardrails can prevent data leakage by screening LLM inputs and outputs for personally identifiable information
https://docs.lakera.ai/docs/data-leakage-prevention (read 2026-09-20)AML.T0086—A tool_call for export_customer_records with an external destination address is ungrounded in the request and leaks customer data — it is detected.
https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
Limit: Dangerous Deviation detector is in beta, ships in a conservative configuration, and is recommended in Detect mode before Enforce.AML.T0048—Ensure your GenAI applications do not violate your organization's policies by detecting and stopping harmful and unwanted content.
https://docs.lakera.ai/docs/defenses (read 2026-09-20)AML.T0082—Attempts to extract hidden system prompts, credentials, or sensitive configurations
https://docs.lakera.ai/red (read 2026-09-20)
Limit: From red teaming, which probes rather than enforces, and names credentials in system prompts and configuration rather than a retrieval corpus.AML.T0083—Examples: write-capable tools; static credentials in toolset configuration; OAuth available but not used.
https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)
Limit: A posture finding surfaced in a risk assessment, not runtime prevention of credential retrieval.
SentinelOne 15 of 76 · partial review
This vendor had a shallower read than the others here, for a reason recorded below. Its count is a floor rather than a comparable figure, and on this page a shallower read has repeatedly meant a lower count rather than a weaker product. It is marked rather than quietly counted.
SentinelOne's AI-security material spans the acquired Prompt Security line, AI-SPM and several dedicated agentic products. Its site publishes no usable sitemap, so pages are found by following links rather than enumerated. A second pass found four agentic products the first had missed and raised its count by six, which is evidence that this method under-reads this vendor rather than evidence that it no longer does — the floor marking stands.
AML.T0010—As soon as a verified advisory is published, agents can then react automatically, flagging risky skills, alerting users, and putting a block on execution paths tied to known issues.
https://www.sentinelone.com/blog/clawsec-hardening-openclaw-agents-from-the-inside-out/ (read 2026-09-20)
Limit: ClawSec is a free open-source skill suite scoped to OpenClaw agents, not the commercial platformAML.T0132—if an Amazon SageMaker notebook instance is configured with direct internet access, AI-SPM generates an exposure and recommends actions to address it
https://www.sentinelone.com/blog/introducing-sentinelones-ai-security-posture-management-ai-spm/ (read 2026-09-20)AML.T0051—Stop prompt injection, jailbreaks, and sensitive data leakage before they reach production or your users
https://www.sentinelone.com/solutions/secure-ai-apps-and-data/ (read 2026-09-20)AML.T0053—inspect tool calls and agent interactions in real time, stopping attacks at the moment of execution
https://www.sentinelone.com/blog/prompt-security-for-agentic-ai/ (read 2026-09-20)
Limit: Described in the future tense as a first phase rather than as shipped behaviour.AML.T0103—Identifies AI-capable runtimes and destinations across the environment, surfacing where agents like OpenClaw are executing.
https://www.sentinelone.com/blog/how-sentinelone-secures-the-ai-tools-that-act-like-users/ (read 2026-09-20)
Limit: framed as shadow-AI hunting, not adversary-deployed-agent detection specificallyAML.T0020—SentinelOne actively scans cloud storage at machine speed to prevent malicious content from ever reaching AI models or applications
https://www.sentinelone.com/blog/ai-security-from-data-to-runtime-a-holistic-defense-approach/ (read 2026-09-20)AML.T0070—Prompt Security automatically preprocesses content before embedding to detect malicious patterns, enforces strict separation between retrieved context and system prompts, and monitors retrieval activity for anomalies or repeated document access that may signal poisoning.
https://prompt.security/blog/the-embedded-threat-in-your-llm-poisoning-rag-pipelines-via-vector-embeddings (read 2026-09-26)AML.T0081—ClawSec is an open-source security skill suite created to harden OpenClaw agents against prompt injection, supply chain compromise, configuration drift, and unsafe runtime behavior.
https://www.sentinelone.com/blog/clawsec-hardening-openclaw-agents-from-the-inside-out/ (read 2026-09-20)
Limit: same ClawSec scope; drift detection alerts, does not blockAML.T0110—identify and block malicious MCP servers from operating in your environment
https://www.sentinelone.com/blog/prompt-security-for-agentic-ai/ (read 2026-09-20)AML.T0054—Stop prompt injection, jailbreaks, and sensitive data leakage before they reach production or your users
https://www.sentinelone.com/solutions/secure-ai-apps-and-data/ (read 2026-09-20)AML.T0007—By treating AI systems as first-class assets, AI-SPM provides a unified inventory of training jobs, development notebooks, managed AI services, and inference endpoints across the environment.
https://www.sentinelone.com/blog/ai-security-from-data-to-runtime-a-holistic-defense-approach/ (read 2026-09-20)
Limit: inventory/posture only; the /platform/ai-security-posture-management page is a live 404, so blog announcement is the only sourceAML.T0084—It parses session logs, configuration files, and runtime artifacts to summarize meaningful usage patterns and surface critical operational details.
https://www.sentinelone.com/blog/oneclaw-discovery-and-observability-for-the-agentic-era/ (read 2026-09-20)
Limit: OneClaw is a standalone discovery/observability tool; inventory only, no enforcementAML.T0133—Map every agent and MCP server in your environment, then govern what they can do.
https://www.sentinelone.com/platform/securing-ai-prompt/ (read 2026-09-20)AML.T0057—Block adversarial prompts and scrub sensitive outputs with a real-time AI firewall
https://www.sentinelone.com/platform/securing-ai-prompt/ (read 2026-09-20)AML.T0086—Correlates secrets access with non-standard egress within the same Storyline, identifying when an agentic assistant has moved from exploration to data exfiltration.
https://www.sentinelone.com/blog/how-sentinelone-secures-the-ai-tools-that-act-like-users/ (read 2026-09-20)
Netskope 17 of 76
Netskope's AI Guardrails documentation states that it maps classified prompts and responses to MITRE ATLAS, making it the one vendor here whose own material references the framework this score is built on.
AML.T0010—For each server, you can view detailed informational attributes and risk-scoring metrics to make informed security decisions.
https://docs.netskope.com/en/app-catalog-and-risk-assessment (read 2026-09-20)AML.T0132—It surfaces misconfigured models, unauthorized data access, and hidden attack paths
https://www.netskope.com/blog/ai-is-everywhere-now-you-can-control-all-of-it (read 2026-09-20)AML.T0011—block malware and malicious links hidden in AI interactions
https://www.netskope.com/products/securing-generative-ai (read 2026-09-20)AML.T0051—protecting from AI threats like prompt injection and jailbreaking
https://docs.netskope.com/en/ai-guardrails (read 2026-09-20)AML.T0053—Agent Action Control gives admins real-time control over these actions through intent-, risk-, and access-based policies.
https://docs.netskope.com/en/agent-action-control (read 2026-09-20)
Limit: Enforcement on one hosted model platform is documented as failing open, and stdio and SSE transports are listed as untested.AML.T0103—Discovery results include AI agents, local LLM processes, local MCP servers, browser AI extensions (Chrome, Edge, Safari), and IDE AI extensions (VS Code, Cursor).
https://docs.netskope.com/en/netskope-client-ai-discovery/ (read 2026-09-20)
Limit: managed Windows/macOS endpoints only, signature-bound; inventory onlyAML.T0020—Netskope One capabilities help ensure that only the right data is used in training by identifying sensitive data and preventing malicious information from being ingested into datastores. This provides protection against data poisoning
https://www.netskope.com/press-releases/netskope-advances-ai-security-with-new-dspm-innovations-as-part-of-netskope-ones-holistic-ai-protection-capabilities (read 2026-09-26)
Limit: Hedged verb (“help ensure”), stated in an April 2025 press release rather than in product documentation.AML.T0054—Inspect every request and response made in 29 languages to identify and stop the sophisticated multi-turn threat from prompt injection and jailbreaking attacks.
https://www.netskope.com/products/ai-guardrails (read 2026-09-20)AML.T0133—Risk assess MCP servers based on its security posture, and classify agent actions by risk level to control what an agent can reach before it executes
https://www.netskope.com/solutions/netskope-one-ai-security (read 2026-09-20)AML.T0085—Inspect tool call arguments, tool call results, and resource content before data reaches the wrong destination.
https://docs.netskope.com/en/mcp-gateway-overview/ (read 2026-09-20)
Limit: the collection-side claim rests on 'tool call results' and 'resource content'; the trailing clause is egress-framedAML.T0056—It encompasses attempts to extract hidden system instructions or manipulate data integrity through poisoned inputs and retrieved documents.
https://docs.netskope.com/en/prompt-library/ (read 2026-09-20)
Limit: AI Red Teaming probe set - pre-deployment testing, not runtime enforcementAML.T0057—inspect every prompt and response in real time to prevent sensitive data such as source code, publicly identifiable information (PII), and intellectual property from leaking
https://www.netskope.com/products/securing-generative-ai (read 2026-09-20)AML.T0086—Administrators can apply access controls to specific tool events and enforce DLP profiles to prevent the leakage of sensitive data.
https://docs.netskope.com/en/granular-control-and-data-loss-prevention-dlp (read 2026-09-20)AML.T0034—AI Gateway 1.7 provides control over AI spend and smoother deployments through token-based rate limiting and automated AWS enrollment.
https://docs.netskope.com/en/ai-gateway-release-notes-version-1-7/ (read 2026-09-20)
Limit: framed as spend/budget control, not abuse or attack detection; release-note summary lineAML.T0048—Automatically filter and control harmful or discriminatory content, including hate speech, crimes, weapons, and violence.
https://www.netskope.com/products/ai-guardrails (read 2026-09-20)AML.T0101—The moment an action crosses into high-risk territory (such as deleting a repository), it is blocked before it executes.
https://www.netskope.com/solutions/netskope-one-ai-security-2 (read 2026-09-20)AML.T0098—Stop AI agents from manipulating credentials and secrets outside of their intended scope, closing off one of the most common paths from an agent action to a breach.
https://www.netskope.com/products/agent-action-control (read 2026-09-20)
Limit: wording is 'manipulating' (create/rotate/export/delete), broader than harvesting
Forcepoint 9 of 76
Forcepoint's AI material describes no prompt-injection or jailbreak capability at all; its AI story is data classification, DLP and an agent gateway. Its AI Data Security datasheet is a password-encrypted PDF and was not read.
AML.T0053—every call is inspected before it executes, and sensitive writes or deletes require human approval
https://www.forcepoint.com/use-case/agentic-ai-security (read 2026-09-20)
Limit: The agent gateway this depends on is documented as pre-general-availability.AML.T0103—Inline endpoint detection surfaces shadow agents operating outside sanctioned AI platforms
https://www.forcepoint.com/use-case/agentic-ai-security (read 2026-09-20)
Limit: shadow-AI governance framing; inventory plus console-driven responseAML.T0133—Discover agents, understand their goals and permissions, and enforce guardrails that keep your data safe
https://www.forcepoint.com/use-case/securely-enable-ai (read 2026-09-20)AML.T0085—Forcepoint classifies sensitive files in OneDrive and SharePoint before Copilot can reach them
https://www.forcepoint.com/ai-data-security (read 2026-09-20)AML.T0057—catches PII in a response, source code in an attachment and credentials pasted into a chat
https://www.forcepoint.com/use-case/ai-prompt-security (read 2026-09-20)AML.T0086—Inline DLP controls where agents access business data, before records are read or written
https://www.forcepoint.com/use-case/agentic-ai-security (read 2026-09-20)AML.T0101—Human-in-the-loop approval gates for writes, deletes and sensitive operations
https://www.forcepoint.com/use-case/agentic-ai-security (read 2026-09-20)AML.T0083—agents calling business applications never receive standing credentials, so a compromised or misbehaving agent has nothing to exploit
https://www.forcepoint.com/use-case/agentic-ai-security (read 2026-09-20)AML.T0098—Every agent-to-application response is inspected at field level, so sensitive values like customer records, source code or credentials get blocked or redacted before an agent can aggregate or transmit them.
https://www.forcepoint.com/blog/insights/top-agentic-ai-security-solutions (read 2026-09-20)
Limit: AI Agent Gateway is stated on the same page as 'currently in early access ahead of general availability'; inline app support only 'spans core enterprise SaaS platforms at launch'
Salt Security 12 of 76
Salt publishes no public product documentation — every cell here comes from marketing pages and its product blog.
AML.T0006—We can spot when an agent is being manipulated or when an MCP server is being used for reconnaissance.
https://salt.security/blog/securing-the-new-ai-edge-why-salt-security-is-bringing-mcp-protection-to-aws-waf (read 2026-09-20)AML.T0132—Identify exposed AI agent APIs and MCP endpoints including rogue, shadow, and misconfigured assets before adversaries do.
https://salt.security/agentic-ai (read 2026-09-20)AML.T0051—Stop prompt injection and context manipulation
https://salt.security/platform (read 2026-09-20)AML.T0053—Identity-Aware Intent Analysis to catch mass data pulls, unauthorized tool usage, and logic-based abuse
https://salt.security/platform (read 2026-09-20)AML.T0020—Model manipulation monitoring: track payloads targeting training endpoints or inference manipulation.
https://salt.security/use-cases/identify-ai-agent-risk (read 2026-09-20)
Limit: Monitoring of API payloads directed at training endpoints only; no claim to identify poisoned samples or clean a dataset.AML.T0080—detecting goal escalation, tool misuse, and role drift before they lead to a breach
https://salt.security/blog/beyond-the-prompt-securing-the-brain-of-your-ai-agents (read 2026-09-20)AML.T0054—Salt inspects how models are actually being used in production, flagging jailbreak attempts, unsanctioned model access, and PII moving into and out of LLM calls.
https://salt.security/platform (read 2026-09-20)AML.T0133—It automatically maps the tools and data sources exposed by each MCP server
https://salt.security/blog/find-the-invisible-salt-mcp-finder-technology-for-proactive-mcp-discovery (read 2026-09-20)AML.T0085—Salt tracks how sensitive data is accessed, shared, and changed across APIs, revealing risk that only appears over time.
https://salt.security/agentic-ai (read 2026-09-20)AML.T0057—Prevent sensitive data loss through model interactions
https://salt.security/platform (read 2026-09-20)AML.T0086—Identify malicious consumption, data exfiltration, scanning, and adversarial discovery.
https://salt.security/agentic-ai (read 2026-09-20)AML.T0083—Salt analyzes every component in your Agentic Security Graph for misconfigurations, excessive permissions, and exposed credentials, before an attacker finds them.
https://salt.security/ (read 2026-09-20)
Limit: Posture-scan detection of exposed credentials across agentic components (the section's own bullets name "Hardcoded tokens and credentials" and "Risky MCP configurations"); inventory/flagging, not runtime prevention of credential read.
BigID 8 of 76
BigID's product documentation is behind a login and was not read. Much of what BigID markets — shadow-AI discovery, account governance — has no adversary-technique row in this set at all.
AML.T0051—The BigID AI Security Platform (AISP) helps protect against prompt injection, model abuse, and vector-store risk.
https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)AML.T0053—BigID mediates agentic tool calls, embeds runtime checks, and flags suspicious behavior
https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)
Limit: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.AML.T0007—BigID automatically scans your data repositories —including S3 buckets, file stores, and databases—to detect files and binaries associated with AI models (e.g., PyTorch, TensorFlow).
https://bigid.com/blog/detecting-shadow-ai-with-bigid/ (read 2026-09-20)
Limit: Inventory-only: detects model files/binaries at rest; no claim to detect an adversary enumerating them.AML.T0084—Find .md files across cloud storage, code repositories, collaboration platforms, and developer workstations.
https://bigid.com/ai-instruction-file-security/ (read 2026-09-20)AML.T0085—During RAG or vector retrievals, BigID uses sensitivity metadata and entitlements to surface only what’s allowed
https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)AML.T0057—Monitor generated responses for sensitive data exposure, policy violations, unauthorized disclosure, and risky output.
https://bigid.com/ai-prompt-security/ (read 2026-09-20)AML.T0086—determine which agents can reach sensitive data, where that information can move, and what to fix before an agent becomes the path out
https://bigid.com/blog/ai-agent-data-exfiltration/ (read 2026-09-20)
Limit: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.AML.T0083—BigID identifies PII, credentials, API keys, proprietary IP, and other sensitive data types within unstructured Markdown content
https://bigid.com/ai-instruction-file-security/ (read 2026-09-20)
Harmonic Security 3 of 76
Harmonic states on its own comparison pages that agent inventory, posture management, agent identities, secrets management and pre-deployment red-teaming are not its product and it is not building them, and answers “No” when asked whether it secures customer-built agents. Those disclaimers are honoured here over its marketing. Most of what it does market — workforce AI usage governance — has no adversary-technique row in this set, so a low count reflects the framework's scope rather than product thinness. Its one inference-endpoint cell is visibility and attribution on managed endpoints, not blocking.
AML.T0040—Harmonic identifies connections to inference endpoints like OpenAI, Anthropic, Bedrock, and Azure AI Foundry, and ties each connection back to the process and user that initiated it.
https://www.harmonic.security/solutions/endpoint-ai-security (read 2026-09-20)
Limit: Managed endpoints only (Harmonic Endpoint Agent); visibility and per-process/per-user attribution of inference-API connections — this sentence claims detection, not blocking.AML.T0133—Automatically discover and inventory all MCP clients (e.g. Codex, Claude Cowork / Code, Cursor) and servers
https://www.harmonic.security/solutions/ai-agent-security-mcp-gateway (read 2026-09-20)AML.T0086—Blocks the MCP Tool request and responds to the AI Agent with details about the type of sensitive data detected
https://docs.harmonicsecurity.app/portal-guides/detection-and-response/configure-scenarios-and-interventions (read 2026-09-20)
Zenity 23 of 76
Zenity Labs contributed several of these techniques to ATLAS; that research is not a product claim and nothing here was scored from it. Zenity's product pages state the capability in a section heading and the attack behaviour in the card beneath, so several quotes below read as a description of the attack rather than as the assertion — the assertion is the line above them on the same page. Its solution briefs are gated PDFs and were not read.
AML.T0118—Agent-to-agent visibility into requests and responses passed between agents.
https://zenity.io/platform/ai-detection-and-response (read 2026-09-20)AML.T0010—A dangerous dependency is blocked by a Boundary before any agent can invoke it again.
https://zenity.io/blog/securing-the-agent-supply-chain (read 2026-09-20)AML.T0132—It evaluates configuration, permissions, and integrations before an agent goes live, and keeps enforcing guardrails automatically as agents evolve.
https://zenity.io/platform/ai-security-posture-management (read 2026-09-20)AML.T0011—running risky skills, files, and code in a sandbox to see what they actually do
https://zenity.io/use-cases/agent-type/coding-personal-agents (read 2026-09-20)AML.T0051—AIDR detects direct and indirect prompt injection and blocks execution before the agent acts on them.
https://zenity.io/platform/ai-detection-and-response (read 2026-09-20)AML.T0053—Flag and block unauthorized tool invocations or API calls that violate policy.
https://zenity.io/platform/ai-detection-and-response (read 2026-09-20)AML.T0070—Detect disguised manipulation attempts embedded in retrieved content or tool results before they influence agent behavior.
https://zenity.io/platform/ai-detection-and-response (read 2026-09-20)AML.T0080—Flags poisoned memory stores and long-term context manipulation across sessions.
https://zenity.io/use-cases/platform/claude-enterprise (read 2026-09-20)AML.T0081—Zenity scans all four Claude configuration scopes, evaluates every hook and skill file for embedded secrets and injection payloads, and enforces MCP allowlists at the org level.
https://zenity.io/use-cases/platform/claude-enterprise (read 2026-09-20)
Limit: Configuration-scan coverage is described for Claude Enterprise scopes/hook/skill files; not stated for other agent platforms.AML.T0099—One agent writes untrusted content into a shared system; a second agent reads it as trusted and acts on it
https://zenity.io/platform/ai-exposure-management (read 2026-09-20)AML.T0110—A malicious or manipulated tool description steers an agent into leaking data or taking an action it was never asked to.
https://zenity.io/platform/mcp-security (read 2026-09-20)AML.T0054—Zenity helps protect against direct and indirect prompt injection, data leakage, and jailbreak attempts.
https://zenity.io/use-cases/platform/security-for-microsoft-365-copilot (read 2026-09-20)
Limit: Hedged verb ("helps protect against"); stated on the Microsoft 365 Copilot page. Corroborated on the Claude Enterprise page, where AIDR's real-time coverage list names "jailbreaks".AML.T0109—A server quietly changes what a tool does after it was approved, so yesterday's safe tool is today's risk.
https://zenity.io/platform/mcp-security (read 2026-09-20)AML.T0007—Zenity discovers every agent and decomposes it into the skills, MCP servers, websites, and repositories it actually uses
https://zenity.io/blog/securing-the-agent-supply-chain (read 2026-09-20)AML.T0084—Each agent comes with its configuration, permissions, and tool access attached
https://zenity.io/platform/ai-observability (read 2026-09-20)AML.T0133—Contextual analysis of agent execution paths, tool invocations, memory updates, decision flows, RAG queries, file access, and user attachments.
https://zenity.io/platform/ai-observability (read 2026-09-20)AML.T0085—An agent reads CRM or ticketing records and writes them somewhere outside approved policy.
https://zenity.io/platform/ai-exposure-management (read 2026-09-20)AML.T0057—Real-time monitoring and blocking of sensitive data leakage leaving through agent conversations, tool calls, or encoded payloads
https://zenity.io/platform/ai-detection-and-response (read 2026-09-20)AML.T0077—AIDR detects risky output such as malicious links, hidden text, and risky image rendering.
https://zenity.io/blog/how-zenity-implements-the-owasp-top-10-for-llm-applications (read 2026-09-26)AML.T0086—An MCP tool call moves PII, secrets, or regulated data to a destination outside policy.
https://zenity.io/platform/mcp-security (read 2026-09-20)AML.T0101—Delete, overwrite, drop, mass-update, deploy, deprovision, and payment operations recognized across every environment.
https://zenity.io/use-cases/risk-type/destructive-actions (read 2026-09-20)AML.T0083—An agent discovers a secret in its own context, an environment variable, a key in a config file
https://zenity.io/platform/agentic-identity-and-access-management (read 2026-09-20)AML.T0108—Identifies command-and-control activity and data exfiltration via model output.
https://zenity.io/use-cases/platform/claude-enterprise (read 2026-09-20)
Limit: Named as an AIDR detection class on the Claude Enterprise page only; no mechanism detail beyond the named detection.
Cycode 10 of 76
Cycode's product documentation is behind a login, so every cell here comes from marketing pages and the official blog. It is the vendor in this table most likely to be under-counted for that reason.
AML.T0132—Prevent excessive permissions and misconfigurations of AI agents and technologies in the ADLC.
https://cycode.com/adlc-security/ (read 2026-09-20)AML.T0051—LLM injection risks, exposed AI API keys, vulnerable AI dependencies, and unsafe AI integrations
https://cycode.com/ai/ (read 2026-09-20)AML.T0053—Block or warn on MCP tool calls that contain secrets or violate your security policies.
https://cycode.com/ai/ (read 2026-09-20)
Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.AML.T0081—Inspect what each rule file contains and understand how it influences AI-generated code in your environment.
https://cycode.com/ai/ (read 2026-09-20)AML.T0007—Discover AI code assistants, models, infrastructure, MCP servers, AI secrets, and AI packages across your software factory.
https://cycode.com/ai/ (read 2026-09-20)AML.T0084—Cycode detects the AI signals traditional security tools miss: commit metadata, AI bot users, rule files, skill files, MCP configurations
https://cycode.com/ai/ (read 2026-09-20)AML.T0057—Scan outbound prompts for secrets, sensitive data patterns, and policy violations in real time.
https://cycode.com/ai/ (read 2026-09-20)
Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.AML.T0086—Tool execution is blocked before anything leaves the IDE
https://cycode.com/blog/ai-guardrails-real-time-ide-security/ (read 2026-09-20)
Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.AML.T0083—Model Context Protocol server connections and AI API keys embedded across repos.
https://cycode.com/ai/ (read 2026-09-20)AML.T0098—Intercept file reads that would expose credentials, PII, or confidential configuration to external AI services.
https://cycode.com/ai/ (read 2026-09-20)
Limit: IDE-boundary control framed as data-leak prevention rather than adversary detection; enforced where Cycode AI Guardrails hooks are installed.
Bifrost Edge 7 of 76
Bifrost is published under Maxim AI; getbifrost.ai redirects there. Its own FAQ routes injection and jailbreak detection to third-party guardrail providers rather than a native detector, so read those two cells as an integration surface. Its image cell rests on content-safety filtering rather than on detecting instructions hidden in an image.
AML.T0051—Catch indirect attacks hidden inside tool results or retrieved content
https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
Limit: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.AML.T0053—you can create a strict allow-list of MCP clients and tools, ensuring that only approved tools can be executed
https://docs.getbifrost.ai/features/governance/mcp-tools (read 2026-09-20)
Limit: Enforcement is a gateway allow-list; Bifrost states it does not execute the tool call itself.AML.T0054—Stop injection and jailbreak attempts before they reach your model
https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
Limit: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.AML.T0084—Edge reads the MCP configuration of supported AI apps on each machine and builds a live inventory
https://docs.getbifrost.ai/edge/mcp-governance (read 2026-09-20)AML.T0057—Redact emails, SSNs, financial, and medical data before they leave your gateway
https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)AML.T0077—Each prompt is inspected before it reaches a model, and each response before it reaches a user
https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)AML.T0034—Bifrost’s budget management system provides comprehensive cost control and financial governance for enterprise AI deployments.
https://docs.getbifrost.ai/features/governance/budget-and-limits (read 2026-09-20)
Ent 0 of 76
Ent's public material contains no occurrence of prompt injection, jailbreak, system prompt, MCP, tool call, poisoning, hallucination or rug pull. It sells insider risk, endpoint data protection and shadow-AI usage control. A zero here is the honest reading of that material against this framework, not an incomplete review.
Nothing in the material read on 2026-09-20 describes coverage for any of these 76 techniques, so every cell is not described. That is a statement about the documentation, not about the product.
Endor Labs 18 of 76
Endor Labs states in its own documentation that these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open. Several cells rest on documentation tables that render client-side.
AML.T0018—Catch unsafe file formats like pickle and unverified PyTorch that can execute code when a model loads.
https://www.endorlabs.com/use-case/ai-model-governance (read 2026-09-20)AML.T0060—Catch hallucinated, typosquatted, and known-malicious packages before the agent runs npm install.
https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)AML.T0115—Models that could be impersonating popular models receive lower scores
https://docs.endorlabs.com/secure-ai-coding/ai-model-scores (read 2026-09-20)AML.T0010—Endor Labs combines visibility into coding agents and their AI supply chain with runtime policy enforcement through native hooks.
https://www.endorlabs.com/use-case/coding-agent-governance (read 2026-09-20)AML.T0132—Examples of what is checked: TLS enforcement, certificate validation, public network binding.
https://docs.endorlabs.com/agent-governance/endor-score/index.md (read 2026-09-20)
Limit: Static, source-and-configuration only — live runtime probes are disabled, so an exposed server is inferred from published source, not observed. Transport and Network Security is one of the three dimensions that contribute findings without a per-dimension score. Blocking depends on an MCP Server Posture policy, which is a guardrail, not a security boundary; enforcement fails open.AML.T0011—Package Firewall blocks malicious packages before a developer or AI agent ever runs the install.
https://www.endorlabs.com/use-case/malicious-package-detection (read 2026-09-20)AML.T0051—Examples of what is checked: Prompt injection, boundary violations, behavioral manipulation in the skill body.
https://docs.endorlabs.com/agent-governance/endor-score/index.md (read 2026-09-20)
Limit: Source-only: an LLM workflow reads the SKILL.md captured at session start and scores it; skills are never executed and there is no runtime prompt inspection (Endor states it frames security "around the agent's actions, not just its prompts"). Enforcement via a Skill Access policy is a guardrail, not a security boundary, and enforcement fails open.AML.T0053—Use this template to govern which MCP servers and tools your agents can call.
https://docs.endorlabs.com/agent-governance/policies (read 2026-09-20)
Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0081—Stops the agent loosening its own guardrails
https://docs.endorlabs.com/agent-governance/policies.md (read 2026-09-20)
Limit: A shipped policy row: it blocks writes to the agent's own settings and hooks, while reads are allowed. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0110—Tool descriptions or inputs that allow instruction override.
https://docs.endorlabs.com/agent-governance/endor-score.md (read 2026-09-20)
Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0109—Endor Labs re-scores a server when its configuration changes, for example a new command, endpoint, transport, or environment variable name.
https://docs.endorlabs.com/agent-governance/endor-score (read 2026-09-20)
Limit: Re-scoring on change is the defence, but the rug-pull behaviour itself is never described. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0084—Review the details section: the source, server type, host, transport, launch command, available tools, and environment variable names.
https://docs.endorlabs.com/agent-governance/inventory (read 2026-09-20)
Limit: Inventory/visibility only. The system policy that guards agent configuration blocks writes, edits and deletes but explicitly allows reads, so discovery of the configuration itself is not blocked. Guardrails, not a security boundary; enforcement fails open.AML.T0133—See every agent, model, MCP server, and skill running across developer workstations and cloud.
https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)AML.T0086—CmdLine: block network exfiltration tools
https://docs.endorlabs.com/agent-governance/policies.md (read 2026-09-20)
Limit: The name of a shipped system policy rather than a described capability. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0101—Block destructive shell commands and risky MCP tool calls
https://www.endorlabs.com/use-case/coding-agent-governance (read 2026-09-20)
Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0112—catches malware before it appears in public databases, protecting developer machines and CI pipelines
https://www.endorlabs.com/use-case/malware-detection (read 2026-09-20)AML.T0083—Missing or weak authentication, secrets exposed in environment variables or source.
https://docs.endorlabs.com/agent-governance/endor-score.md (read 2026-09-20)
Limit: A scoring dimension rather than an enforced block. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.AML.T0098—Block destructive shell commands, credential reads, and risky tool calls at the hook layer
https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)
Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
Certiv 14 of 76
Certiv is unusually explicit about what has not shipped. Its context-aware decision engine, divergence detection, pre-load MCP inventory and session-start config scanning are all labelled roadmap or not enforced today, and none of them is counted here — which is why Certiv scores nothing for discovering or protecting agent configuration.
AML.T0093—Flag prompt injection in emails, docs, shell output
https://certiv.ai/openclaw/ (read 2026-09-26)AML.T0132—Certiv Scout finds AI agents and local model runtimes on every endpoint, including Ollama, LM Studio, llama.cpp servers, and other local services.
https://certiv.ai/local-models/ (read 2026-09-20)AML.T0011—Blocks adding a new external dependency (npm install, pip install, go get, cargo add, or a manifest edit) that the user did not explicitly ask for.
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
Limit: The gate is "the user did not explicitly ask for it", not a malware verdict — Certiv makes no claim to identify a package as malicious, and a dependency the user does request is not checked. Semantic (model-judged) check; action is tunable per enrollment.AML.T0051—Detect agents acting on injected instructions that override intended behavior.
https://certiv.ai/product/ (read 2026-09-20)AML.T0053—Certiv intercepts the agent's proposed tool call and evaluates it before it executes.
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)AML.T0103—Blocks running a known AI agent CLI, including bare-name, path-qualified, npx, and detached-wrapper forms like nohup, tmux, screen, and setsid.
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)AML.T0080—Memory segmentation + context integrity checks + session isolation + drift detection on stored state
https://certiv.ai/security-teams/ (read 2026-09-20)AML.T0099—Treat tool output and repo text as untrusted
https://certiv.ai/openclaw/ (read 2026-09-20)AML.T0110—Certiv authorizes each MCP tool call against policy on the endpoint today
https://certiv.ai/coding-agents/ (read 2026-09-20)AML.T0068—Catches obfuscated attacks and hidden-text injection that regex misses.
https://certiv.ai/coding-agents/ (read 2026-09-20)AML.T0086—Blocks a tool call only when it actually transmits sensitive data (secrets, keys, .env contents, proprietary source) outbound to a remote host.
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)AML.T0034—See abnormal token usage, set budgets, and protect against runaway sessions.
https://certiv.ai/blog/token-spend-signal-rogue-agent/ (read 2026-09-20)
Limit: Certiv states this capability is in public preview.AML.T0101—Blocks irreversible destruction in any phrasing: rm -rf, git push --force, DROP TABLE, TRUNCATE, unbacked overwrites, and volume purges.
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)AML.T0098—Blocks reads of credentials from environment variables, tool calls that read or modify .env, ~/.ssh, ~/.aws, ~/.kube, ~/.gnupg, or ~/.docker
https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
Backslash Security 14 of 76
No public documentation site exists; every cell comes from Backslash's own marketing pages plus one official GitHub README.
AML.T0010—Backslash secures your agentic fabric from malicious, compromised, and untrusted external components.
https://www.backslash.security/use-cases/supply-chain-security (read 2026-09-20)AML.T0132—Backslash evaluates MCP servers for vulnerabilities, excessive permissions, supply chain risks, insecure configurations, network exposure, and malicious behaviors.
https://www.backslash.security/use-cases/mcp-security (read 2026-09-20)AML.T0011—Backslash rates every MCP server, skill, and plugin on its security posture and supply-chain risk, then lets you allowlist, blocklist, or require approval before installation.
https://www.backslash.security (read 2026-09-20)AML.T0051—Identify when injected instructions attempt to manipulate tool selection, access sensitive resources, execute unauthorized code, escalate privileges, or transmit data to unapproved destinations.
https://www.backslash.security/use-cases/prompt-injection-security (read 2026-09-20)AML.T0053—Backslash's endpoint MCP proxy inspects communication between AI agents and MCP servers in real time, blocking malicious instructions, risky tool calls, excessive permissions, and policy violations.
https://www.backslash.security/use-cases/mcp-security (read 2026-09-20)AML.T0103—Block unapproved AI agents and assets on the endpoint.
https://www.backslash.security/use-cases/agentic-endpoint-security (read 2026-09-20)AML.T0081—identifying prompt injections, network exposure, supply chain poisoning and configuration drift
https://www.backslash.security/use-cases/agentic-endpoint-security (read 2026-09-20)AML.T0110—Backslash parses Skill files and their supporting scripts, and assesses MCP servers and their exposed tools, identifying hidden instructions, malicious intent, and behavior that exceeds what the component advertises.
https://www.backslash.security/use-cases/prompt-injection-security (read 2026-09-20)AML.T0109—Continuously evaluate agentic components and their dependencies for malicious instructions, unsafe scripts, suspicious updates, untrusted publishers, excessive permissions, hidden external connections, and other supply chain risks.
https://www.backslash.security/use-cases/supply-chain-security (read 2026-09-20)AML.T0133—Map who uses each agent, how it was installed, which models and components it loads, what permissions it holds, which tools it can invoke
https://www.backslash.security/use-cases/rogue-agents (read 2026-09-20)AML.T0057—Monitor for anomalous activity in real time, detect and prevent data leakage, prompt injections, privilege escalations and drift.
https://www.backslash.security/agentic-endpoint-security (read 2026-09-20)AML.T0086—Backslash monitors runtime activity and blocks risky actions such as data exfiltration, unauthorized tool execution, prompt injection, and policy violations before damage occurs.
https://www.backslash.security/use-cases/agentic-endpoint-security (read 2026-09-20)AML.T0112—Prevent data exfiltration, unauthorized code execution, privilege escalation, and other risky actions that are the result of compromised or malicious skills.
https://www.backslash.security/use-cases/agent-skills-security (read 2026-09-20)AML.T0083—Scans for potential secrets and API keys
https://github.com/backslash-security/Claw-Hunter (read 2026-09-20)
Limit: Free standalone Claw-Hunter script for OpenClaw only; read-only scan of the agent install/config, not platform-wide enforcement.
Kitecyber 4 of 76
Kitecyber's blog is largely third-party-sourced and its FAQ hedges several claims; only unhedged first-person product copy was scored. One cell was removed because neither “MCP” nor “Model Context Protocol” appears anywhere on its site, so the credit had no supporting evidence. Its case study and comparison datasheets are behind a form.
AML.T0051—Allow approved actions while automatically blocking unauthorized data access, risky transfers, and prompt injection attempts.
https://www.kitecyber.com/ai-security/ (read 2026-09-20)AML.T0084—The endpoint agent inventories every AI agent and the skills it loads.
https://www.kitecyber.com/ai-security/ (read 2026-09-20)
Limit: Inventory of agent configuration and loaded skills; not runtime enforcement.AML.T0085—Know the moment an agent touches sensitive data on the endpoint — PII, source code, secrets, financial or regulated records.
https://www.kitecyber.com/ai-security/ (read 2026-09-20)
Limit: Endpoint-local detection/alerting on agent access to sensitive data; no RAG-database coverage.AML.T0086—Stop sensitive data from being exfiltrated off the device by an agent in real time
https://www.kitecyber.com/ai-security/ (read 2026-09-20)
Straiker 22 of 76
Straiker's product documentation sits behind a login and was not read. Its published attack-coverage matrix lists further techniques as single-cell labels with no prose, so they carry no quotable claim and are not counted here — real coverage that the evidence rule cannot admit.
AML.T0118—Straiker secures multi-agent systems by monitoring agent-to-agent communication and tool-delegation chains.
https://www.straiker.ai/solution/custom-built-agents (read 2026-09-20)AML.T0010—Defend AI identifies malicious, poisoned, or vulnerable MCP servers in real time using Straiker's MCP Threat Database, helping prevent supply chain attacks and unauthorized data access.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0132—Detect over-permissioned agents, risky MCP connections, and misconfigured integrations across your full agentic ecosystem.
https://www.straiker.ai/products/discover-ai (read 2026-09-20)AML.T0051—it inspects every prompt, reasoning step, and tool call to stop prompt injection, data exfiltration, and agent manipulation in real time
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0053—Defend AI enforces runtime guardrails on every tool call, blocking unauthorized actions and data exfiltration at 98%+ accuracy and low latency.
https://www.straiker.ai/solution/mcp-security (read 2026-09-20)
Limit: Blocking requires the inline deployment; other deployments are documented as detection only.AML.T0100—Keep agents on approved domains and workflows, intercepting redirects, shortlinks, and iframe handoffs that could steer sessions toward untrusted or malicious destinations.
https://www.straiker.ai/solution/runtime-guardrails-for-agentic-web-browsers (read 2026-09-20)AML.T0103—Straiker's Discover AI maps every agent, tool connection, and MCP integration so security teams can detect unknown agents, shadow deployments, and unauthorized access paths.
https://www.straiker.ai/products/discover-ai (read 2026-09-20)
Limit: Discovery/inventory of unknown and shadow agent deployments; containment is a separate product (Agentic Kill Switch).AML.T0080—It detects and blocks identity abuse, memory poisoning, data exfiltration, and resource exploitation at runtime, without slowing down the agents your business depends on.
https://www.straiker.ai (read 2026-09-20)AML.T0081—It can detect and block actions such as file deletion and configuration changes while protecting proprietary code and secrets in development environments.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0099—Defend AI detects data exfiltration across SaaS applications, blocks prompt injection delivered through enterprise content like emails and documents, and surfaces unapproved agent usage.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0110—enforces runtime policy to stop tool poisoning, malicious skills, rug pulls, output injection, and unauthorized actions
https://www.straiker.ai/solution/mcp-security (read 2026-09-20)AML.T0054—Straiker monitors every step at runtime by catching jailbreaks, enforcing safe tool use, and flagging compliance gaps.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0109—Ascend AI continuously red-teams your MCP connections, testing for tool poisoning, rug pulls, and privilege escalation.
https://www.straiker.ai/solution/mcp-security (read 2026-09-20)
Limit: From red-team testing, which probes for this rather than enforcing against it at runtime.AML.T0129—Detect threats hidden in text, code, images, audio, and file uploads that single-mode tools miss.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0133—Uncover MCP servers & Claude Skills connected to your agents and map how they extend agent capabilities
https://www.straiker.ai/products/discover-ai (read 2026-09-20)AML.T0056—Runtime AI guardrails address both non-agentic risks like prompt injection, system prompt leaks, harmful or toxic content, and data exfiltration
https://www.straiker.ai/solution/guardrails (read 2026-09-20)AML.T0057—Defend AI uses semantic detection to identify data exfiltration attempts across all agent types.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0086—Straiker blocks destructive actions, data exfiltration of company secrets, and malicious MCP connections at runtime.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0029—Denial-of-service patterns including excessive API calls, infinite loops, and compute abuse that drain system resources.
https://www.straiker.ai/solution/genai-and-agentic-ai-threat-detection (read 2026-09-20)AML.T0048—Detect and suppress application drift, toxic output, and policy violations before they reach users or downstream systems.
https://www.straiker.ai/products/defend-ai (read 2026-09-20)AML.T0101—Straiker detects and blocks data exfiltration, remote code execution, destructive infrastructure actions, tool misuse, and resource exhaustion in real time.
https://www.straiker.ai/solution/coding-agents (read 2026-09-20)AML.T0112—Straiker detects the injection path and blocks the action at runtime, before code runs.
https://www.straiker.ai/anthropic-claude (read 2026-09-20)
MIND 4 of 76
MIND publishes its own scope boundary and it is honoured here over its adjacent marketing: “Instead of securing models or reacting to outputs, MIND ensures sensitive data is understood, governed and protected before any AI agent can access or act on it”, and, on an autonomous-agent breach post, “MIND doesn’t patch template-injection flaws or contain a sandbox escape. No data loss prevention platform does.” It is a data loss prevention and insider-risk platform, so most of this framework is not its subject: on /solutions/secure-agentic-ai, its most agentic page, “prompt injection”, “jailbreak”, “MCP” and “tool call” each occur zero times against 93 occurrences of “agent”. The low count is not a thin-corpus artefact — 184 pages and roughly 174,000 words were read, a corpus comparable to vendors scoring four times higher. A strongly worded agentic sentence on its newsroom page was left uncredited because it is Frost & Sullivan’s prose republished by MIND, not MIND’s own claim.
AML.T0103—Continuously discover which AI agents are running across your environment, including embedded SaaS capabilities, custom-built agents and third-party tools.
https://mind.io/solutions/secure-agentic-ai (read 2026-09-20)
Limit: Inventory and visibility only — shadow-agent discovery, not detection of an adversary launching an agent.AML.T0085—See what data AI agents interact with and how it’s used, so sensitive information stays protected and aligned with policy.
https://mind.io/solutions/secure-agentic-ai (read 2026-09-20)
Limit: Visibility of what data agents reach, from the data side (endpoint agent, browser extension, SaaS connectors); no claim to inspect RAG retrievals or agent tool results.AML.T0057—With the lightweight endpoint agent and browser extension, MIND can protect sensitive data across GenAI tools, from prompt to response.
https://mind.io/solutions/data-source-genai (read 2026-09-20)AML.T0086—When sensitive data starts moving somewhere it shouldn’t, whether at rest or in motion, MIND blocks the exfiltration in real time instead of filing an alert for the morning queue.
https://mind.io/blog/hugging-face-breach-autonomous-ai-agent-dlp (read 2026-09-20)
Limit: Egress data-loss control at the endpoint, browser and SaaS layer; MIND nowhere claims to intercept or evaluate an agent tool call itself.
WitnessAI 14 of 76
WitnessAI is first a network-layer governance product for employee and agent AI use: discovery against a catalogue of 4,000+ apps, intent-based policy, tokenisation, model routing and AI FinOps. Most of that has no adversary-technique row in this set, so a large share of its marketing earns nothing here. Its cells come from Witness Protect, an AI firewall for prompts and responses; Agentic Control, an approved-list of MCP servers and tools that it says is enforced before a call executes, launched 17 June 2026; and Witness Attack, pre-deployment red teaming, whose cells are bounded. WitnessAI scopes its own agent protection to “supported agent workflows” and to “traffic governed through the platform”, and that limit is carried on the tool-invocation cell. Its product documentation at docs.witness.ai is password-protected. All 191 pages in its sitemap returned a password form, so nothing was scored from them. The page titles alone suggest that Witness Anywhere installs a binary through Intune, Jamf, GPO or EDR, while the marketing says “no endpoint clients”. That is unverified. Several recurring claims were not credited. Tokenising credentials in prompts is usage DLP, not an agent harvesting credentials. “Hallucinated outputs” is output quality, not an adversary. A sentence about indirect injection in emails and documents describes no mechanism beyond the prompt-injection detection already counted. Read 2026-09-27: the full marketing sitemap (about 310 pages, mostly blog posts) plus 10 first-party PDFs.
AML.T0118—It sits between users and AI applications to observe, classify, and enforce policy on prompts, responses, tool calls, and inter-agent activity in real time.
https://witness.ai/blog/multi-agent-security/ (read 2026-09-27)AML.T0010—Once those tools are visible, the new MCP Catalog scores each against OWASP and CVE risk classes, so the team weighs a server’s exposure and approves it on evidence rather than a name.
https://witness.ai/blog/introducing-witnessai-agentic-control-one-control-plane-for-every-agent-tool-and-mcp-server/ (read 2026-09-27)AML.T0051—Detect and mitigate prompt injections, jailbreaks, and other AI-specific threats before they compromise your business.
https://witness.ai/protect/ (read 2026-09-27)AML.T0053—Govern every form of agent deployment, from custom cloud agents to agentic IDEs, with enforcement at the tool call and MCP server level.
https://witness.ai/control/ (read 2026-09-27)
Limit: An approved-list control: WitnessAI describes it as denying MCP servers and tools that are off the list before they execute, not as judging what an approved tool is asked to do. WitnessAI itself scopes it to “traffic governed through the platform” and, on its home page, to “supported agent workflows”.AML.T0103—Scan your entire network for third-party AI applications and agents for complete visibility into AI adoption and risk exposure across your human and digital workforce.
https://witness.ai/observe/ (read 2026-09-27)
Limit: Network-level shadow-AI and shadow-agent discovery; inventory, not detection of an adversary launching an agent.AML.T0110—Witness Attack —proactive testing before deployment, which validates that MCP server integrations don’t introduce tool poisoning, injection, or over-privilege risks before they reach production.
https://witness.ai/blog/mcp-server-security/ (read 2026-09-27)
Limit: From pre-deployment red teaming (Witness Attack), which tests for tool poisoning rather than enforcing against it at runtime.AML.T0054—WitnessAI’s Model Protection Guardrail directly addresses this challenge by detecting jailbreak attempts at every stage of the adversarial process
https://witness.ai/blog/closing-the-loop-how-witnessai-stops-reasoning-leakage-jailbreaks-at-every-phase/ (read 2026-09-27)AML.T0068—By analyzing the intent behind the prompt, WitnessAI ensures that even obfuscated or indirect attacks are detected.
https://witness.ai/wp-content/uploads/2024/12/WIT-24-010_Model-Protection-Guardrail-Solutions-Brief.pdf (read 2026-09-27)AML.T0129—Using multimodal attack vectors, multi-step jailbreaks, and reinforcement-learning techniques, our AI red teaming stress-tests your model defenses and provides actionable insights for hardening.
https://witness.ai/protect/ (read 2026-09-27)
Limit: From pre-deployment red teaming (Witness Attack), which probes with multimodal attacks rather than inspecting multimodal inputs at runtime; no runtime multimodal inspection is claimed.AML.T0133—Discover which agents are running and what external MCP servers and tools they connect to
https://witness.ai/ (read 2026-09-27)AML.T0057—Response protection inspects what comes back, catching harmful content and leaked secrets on the way out.
https://witness.ai/blog/prompt-injection-mitigation-strategies/ (read 2026-09-27)AML.T0086—Prevent coding agents from exposing proprietary code when calling external tools.
https://witness.ai/for-developers/ (read 2026-09-27)AML.T0034—Stop consumer abuse of B2C AI apps for non-profitable prompts.
https://witness.ai/for-finops/ (read 2026-09-27)
Limit: Framed as AI FinOps spend control — blocking or rerouting prompts classified as non-productive — rather than detection of deliberate cost harvesting.AML.T0048—Filter harmful responses before end users see them
https://witness.ai/ (read 2026-09-27)
Lasso Security 23 of 76
Lasso's product documentation, a GitBook, redirects to a login and was not read. Everything here comes from its marketing site, blog, three first-party PDFs and its open-source GitHub repositories. Two cells come from the open-source MCP Gateway rather than the commercial platform and carry that scope as a limit. Lasso's open-source Claude Code hook states that it “warns but does not block”. That is honoured as the scope of that tool and is not assumed of the enterprise hook deployment, which Lasso says flags or blocks. Lasso publishes its own OWASP and MITRE ATLAS mapping of its policies in a PDF titled Compliance and Threats Mapping. As with badge-style mappings elsewhere, the technique IDs there carry no product prose. No cell was scored from the mapping itself, only from one policy description that has a sentence of its own. Red-team reconnaissance that “extracts the system prompt” and identifies the underlying model was not counted, because it is attack targeting, not a finding or a defence. A 2025 blog attributes memory isolation to an MCP Gateway plugin that the gateway's own README does not list, so that claim was not used. Read 2026-09-27: the full sitemap (282 pages, 4 of them 404), 3 PDFs and 3 GitHub READMEs.
AML.T0118—Track how intent transforms through complex chains, alerting if intent is "corrupted" or "inverted" as it passes between different agents.
https://www.lasso.security/platform/intent-security (read 2026-09-27)AML.T0010—Secure the supply chain by assessing commercial, open-source, or custom-made models for inherent vulnerabilities and building policies that mitigate the risks.
https://www.lasso.security/platform/ai-application-security (read 2026-09-27)AML.T0132—Identify misconfigurations, risky tool access, weak guardrails, exposed dependencies, and potential attack paths, showing how an attacker could potentially move through the agentic workflow.
https://www.lasso.security/platform/ai-security-posture-management (read 2026-09-27)AML.T0011—Blocks risky MCPs based on reputation scores (threshold: 30) and security analysis
https://github.com/lasso-security/mcp-gateway (read 2026-09-27)
Limit: Lasso's open-source MCP Gateway security scanner, which gates MCP servers on a reputation score built from marketplace (Smithery, NPM) and GitHub data plus tool-description scanning; it is a reputation threshold, not a malware verdict, and applies only to servers routed through the gateway.AML.T0051—Detect and block prompt injection in real-time across AI agents, chatbots, and LLM applications.
https://www.lasso.security/use-cases/prompt-injection-protection (read 2026-09-27)AML.T0053—Lasso inspects every tool call before it is executed. Security teams define what tools are permissible within a given scope, and anything outside that scope is flagged or blocked.
https://www.lasso.security/use-cases/ai-coding-assistants (read 2026-09-27)AML.T0103—Discover, inventory, and assess every AI asset across your enterprise, from models to SaaS and web chatbots to local desktop agents or homegrown agents and their connected tools.
https://www.lasso.security/platform/ai-usage-control (read 2026-09-27)
Limit: Shadow-AI and agent discovery with risk scoring; Lasso says a high-risk agent can be blocked, but it is not framed as detection of an adversary deploying an agent.AML.T0070—Lasso identifies content that attempts to alter the agent's behavior after retrieval, and names the source document.
https://www.lasso.security/blog/owasp-top-10-for-llm-applications-2026-what-changed-what-surprised-us-what-matters (read 2026-09-27)AML.T0080—Monitor every agent action and MCP tool call in real-time to identify indirect prompt injection, memory poisoning, data exfiltration, tool poisoning, malicious responses, and other AI threats or attack techniques.
https://www.lasso.security/use-cases/agentic-ai-risk-management (read 2026-09-27)AML.T0099—Lasso scans content and identifies injected instructions embedded in files, web responses, or MCP outputs, which are flagged before they reach the agent’s decision layer.
https://www.lasso.security/use-cases/ai-coding-assistants (read 2026-09-27)AML.T0110—Scan MCP server tool descriptions for hidden instructions. Detect and block prompt injection attempts at the connection layer.
https://www.lasso.security/use-cases/mcp-security (read 2026-09-27)AML.T0054—Enable security by design with policies for content moderation, data protection, and AI threats like prompt injection and jailbreak, ensuring that as your models and applications evolve, your enforcement remains consistent.
https://www.lasso.security/platform/ai-application-security (read 2026-09-27)AML.T0068—Detect over 3,000 evasion techniques including Base64 and hex encoding, Unicode homoglyph substitution, invisible character manipulation, leet speak, and cross-lingual attacks that mix languages to bypass filters.
https://www.lasso.security/use-cases/prompt-injection-protection (read 2026-09-27)AML.T0084—Identify the owner, the LLM in use, the system prompt, policies, tool registry, and guardrails, and keep it current with every deployment change.
https://www.lasso.security/platform/discovery-ai-bom (read 2026-09-27)
Limit: Inventory of the defender's own agents (read-only CI and cloud-platform integrations), not detection of an adversary enumerating agent configuration.AML.T0133—Inventory every agentic application, the tools and MCP servers they call, and the resources they have access to.
https://www.lasso.security/platform/ai-security (read 2026-09-27)AML.T0085—Lasso monitors query and response behavior and validates access permissions at runtime, so users don’t retrieve sensitive information they wouldn’t otherwise be authorized to access.
https://www.lasso.security/use-cases/public (read 2026-09-27)AML.T0056—Detection compares the meaning of the model's output against the meaning of the protected instructions, rather than their wording.
https://www.lasso.security/blog/owasp-top-10-for-llm-applications-2026-what-changed-what-surprised-us-what-matters (read 2026-09-27)AML.T0057—Lasso prevents PHI from leaking in AI responses by inspecting and controlling model outputs in real time before they reach the user.
https://www.lasso.security/use-cases/healthcare (read 2026-09-27)AML.T0086—Detect and monitor in real-time if PII, API keys, credentials, or any other sensitive data is shared through MCP tool calls. Mask sensitive contents before they reach external servers.
https://www.lasso.security/use-cases/mcp-security (read 2026-09-27)AML.T0029—Lasso's agent rate-limiting and compute quota controls prevent abuse, offering automatic suspensions and monitoring to avoid overload scenarios
https://www.lasso.security/blog/agentic-ai-security-threats-2025 (read 2026-09-27)AML.T0034—It prevents resource exhaustion, runaway agent behavior, and cost-based denial of service by applying dynamic constraints on tokens, tool calls, execution time, and spend - before requests reach the model.
https://143238628.fs1.hubspotusercontent-eu1.net/hubfs/143238628/NIST%202026/Lasso_Compliance_Mapping.pdf (read 2026-09-27)AML.T0048—Define exactly what topics can and cannot be discussed with AI according to your use case and industry requirements, while blocking standard risks like hate speech, violence, and more.
https://www.lasso.security/platform/ai-usage-control (read 2026-09-27)AML.T0098—MCP Gateway will automatically mask the sensitive token in the response, preventing exposure of credentials while still providing the needed functionality.
https://github.com/lasso-security/mcp-gateway (read 2026-09-27)
Limit: The open-source gateway's basic plugin masks the token types it lists (cloud, GitHub, GitLab, Hugging Face, JWT, Slack and similar) in MCP tool responses routed through the gateway; pattern masking, not detection of harvesting intent.
Pillar Security 26 of 76
Pillar documents more of this framework in its own words than any vendor reviewed so far, and most of it sits in first-party blog announcements rather than on its product pages. Its documentation site is behind a login and was not read, so the mechanics behind these claims (how the endpoint sensor intercepts a tool call, what reaches Pillar's cloud) are stated only at marketing depth. About 350 pages were read on 27 September 2026: product and solution pages, all 135 blog posts and the research pages. The 92 SAIL framework pages and 73 risk-glossary pages are Pillar's open framework, not product claims, and nothing was scored from them; neither was its vulnerability research, the Frost & Sullivan and Latio analyst prose it quotes, or single-cell labels. Red-team findings are credited only as bounded cells, and inventory as bounded cells. A homepage alert about an agent pulling 2,300 customer emails from Agentforce was not scored as data collection, because Pillar itself labels it exfiltration, which is already credited.
AML.T0118—In orchestration workflows, Pillar inspects every inter-agent handoff and intercepts poisoned instructions before they reach dependent agents.
https://www.pillar.security/solutions (read 2026-09-27)AML.T0010—The Pillar platform discovers and flags malicious GGUF files and other types of risks in the template layer.
https://www.pillar.security/blog/llm-backdoors-at-the-inference-level-the-threat-of-poisoned-templates (read 2026-09-27)AML.T0093—Triggered when a workflow invokes an agent in response to user-controlled events such as issue comments or pull-request descriptions.
https://www.pillar.security/blog/introducing-pillar-for-agentic-ci-cd (read 2026-09-27)
Limit: A posture finding on CI/CD workflow configuration (SAIL 5.3) that flags an agent reachable by public input. It does not detect the injected prompt when it arrives.AML.T0132—Pillar detects the open endpoint during infrastructure scanning and flags it as a critical external exposure.
https://www.pillar.security/platform (read 2026-09-27)AML.T0011—with sandbox execution to observe what a skill actually does, and high-risk ones blocked at the endpoint, the corporate gateway, or the agent's admin console
https://www.pillar.security/blog/pillar-security-named-an-ai-security-technical-innovator-in-the-latio-2026-ai-security-market-report (read 2026-09-27)AML.T0051—Prompt injection protection. Block direct and indirect injection attempts before they manipulate your model or agent.
https://www.pillar.security/blog/pillar-truefoundry-runtime-ai-protection-built-into-the-gateway (read 2026-09-27)AML.T0053—Our runtime guardrails sit at the same architectural seam as harness hooks, blocking dangerous tool calls at decision time rather than reporting on them after the fact.
https://www.pillar.security/blog/your-agent-harness-has-more-privilege-than-your-agent (read 2026-09-27)AML.T0103—In the hackerbot-claw scenario, agents running with maximum-permissive flags would have been flagged immediately - whether spawned by a developer or a compromised extension.
https://www.pillar.security/blog/hackerbot-claw-adversarial-agent-targets-top-github-repos (read 2026-09-27)
Limit: Stated as a counterfactual about one campaign. The detection is keyed to permission-bypassing launch flags found by configuration scanning, not to the launch of an agent as such.AML.T0070—Injection Blocking : Stop malicious instructions in user or retrieved content.
https://www.pillar.security/platform/runtime-guardrails (read 2026-09-27)AML.T0080—It plans and runs adversarial campaigns against complete agentic workflows, probing for goal hijacking, indirect prompt injection, tool misuse, memory poisoning, and privilege escalation
https://www.pillar.security/blog/pillar-security-named-a-pioneer-in-the-2026-gartner-r-emerging-market-quadrant-for-ai-application-security (read 2026-09-27)
Limit: From red teaming (RedGraph Suite), which probes for memory poisoning rather than enforcing against it at runtime.AML.T0081—The sensor catches the behaviors that matter on a developer laptop: an agent modifying its own configuration
https://www.pillar.security/blog/pillar-security-named-an-ai-security-technical-innovator-in-the-latio-2026-ai-security-market-report (read 2026-09-27)AML.T0099—Pillar's detection operates on the full session, so injected instructions embedded in a retrieved document or tool response get caught even when the individual turn looks benign in isolation.
https://www.pillar.security/blog/pillar-truefoundry-runtime-ai-protection-built-into-the-gateway (read 2026-09-27)AML.T0110—Tool poisoning detection triggers when agents execute unauthorized commands based on poisoned MCP metadata.
https://www.pillar.security/blog/introducing-pillar-for-ai-coding-agents (read 2026-09-27)AML.T0054—Jailbreak detection. Catch attempts to bypass safety controls, including multi-turn and obfuscated variants.
https://www.pillar.security/blog/pillar-truefoundry-runtime-ai-protection-built-into-the-gateway (read 2026-09-27)AML.T0068—Identify any attempt to perform app fingerprinting or evade detection using hidden characters or encoding techniques.
https://www.pillar.security/blog/pillar-truefoundry-runtime-ai-protection-built-into-the-gateway (read 2026-09-27)AML.T0109—Our MCP security layer audits tool descriptions and registries for the drift and poisoning that bypasses every model-level defense.
https://www.pillar.security/blog/your-agent-harness-has-more-privilege-than-your-agent (read 2026-09-27)AML.T0007—Pillar catalogs agents, models, prompts, tools, MCP servers, and coding agents through agentless integrations with source code repos, data platforms, and endpoints.
https://www.pillar.security/platform/ai-discovery-posture (read 2026-09-27)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0084—Maps instructions, data sources, tool permissions, and external connections per agent.
https://www.pillar.security/platform (read 2026-09-27)
Limit: An inventory of each agent's configuration. It does not detect an adversary who is enumerating that configuration.AML.T0133—Autonomous reconnaissance captures an agent's system prompt, tools, knowledge, and permissions with no code changes
https://www.pillar.security/blog/pillar-launches-red-graph-suite-version-controlled-contextual-and-continuous-ai-red-teaming (read 2026-09-27)
Limit: From red teaming, which performs the capability discovery itself rather than enforcing against it at runtime.AML.T0056—System Prompt Protection : Prevent extraction or manipulation of instructions.
https://www.pillar.security/platform/runtime-guardrails (read 2026-09-27)AML.T0057—Identify, mask, or block PII, PHI, secrets, and credentials in AI interactions.
https://www.pillar.security/platform/runtime-guardrails (read 2026-09-27)AML.T0086—Pillar tracks tool invocations across every agent session, mapping multi-step chains to detect cascading exfiltration and privilege escalation before data leaves your environment.
https://www.pillar.security/solutions (read 2026-09-27)AML.T0048—Content moderation and toxicity filtering. Keep outputs clean, safe, and compliant with enterprise policy.
https://www.pillar.security/blog/pillar-truefoundry-runtime-ai-protection-built-into-the-gateway (read 2026-09-27)AML.T0112—a dangerous command executed right after the agent read from an untrusted external source
https://www.pillar.security/blog/pillar-security-named-an-ai-security-technical-innovator-in-the-latio-2026-ai-security-market-report (read 2026-09-27)AML.T0083—identifies hardcoded credentials for production databases and cloud services in MCP configurations
https://www.pillar.security/blog/introducing-pillar-for-ai-coding-agents (read 2026-09-27)
Limit: A configuration-posture finding about credentials stored in MCP configuration. It does not prevent an adversary reading them at runtime.AML.T0098—Rapid sequential access to credential files signals harvesting attempts.
https://www.pillar.security/blog/introducing-pillar-for-ai-coding-agents (read 2026-09-27)
Limit: A behavioural-baseline alert on rapid, sequential reads of credential files, which Pillar describes as a deviation that triggers an alert. A single credential read by an agent is not claimed.
Permiso 9 of 76
Permiso sells identity threat detection and response and now carries an Okta banner. It treats AI agents as another class of identity, and it says so plainly: it argues against prevention by guardrails and calls for runtime visibility and containment. It also describes model-layer concerns such as prompt injection as not where most enterprise AI incidents will start. Its coverage is therefore identity-layer and log-based. It attributes agent runs and tool calls to identities, detects anomalies, revokes access with a kill switch, and sandboxes skills in SandyClaw. It makes no claim to inspect prompts or tool arguments before they execute. About 190 pages were read on 27 September 2026: product and solution pages, 107 blog posts and the resource library. The documentation site is password-protected and was not read. Nothing was scored from P0 Labs research, including its LLMjacking, Copilot cross-prompt-injection and malicious-skill work. Its sentence that detections are built on prompt injection observed in the wild names where its detections come from, not a capability, so it earns no cell. The 35-plus exposure table mapped to OWASP (entries such as agent self-modification and agent can disable logs) is single-cell labels with no prose, so it is not counted.
AML.T0118—Session-level evidence and runtime data provide forensic trails for understanding how identities interact across agent networks.
https://permiso.io/blog/8-critical-ai-security-challenges (read 2026-09-27)
Limit: A forensic trail of the identity and authorisation chain between agents. No detection is described, and the content agents pass to one another is not inspected.AML.T0132—Permiso analyzes your AI infrastructure and agents for key security issues, including over-permissioning, weak authentication controls, and configuration vulnerabilities.
https://permiso.io/blog/permiso-delivers-complete-ai-security-through-unified-identity-platform (read 2026-09-27)AML.T0011—SandyClaw runs every skill in a controlled sandbox before it touches your environment, recording every action, every tool call, every downstream request.
https://permiso.io/ai-security (read 2026-09-27)AML.T0053—Permiso detects over-privileged access, unused permissions, anomalous tool usage, policy violations, and high blast radius behavior in real time.
https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
Limit: Anomaly detection on tool calls attributed from logs to an identity. The stated response is an identity-layer kill switch once behaviour crosses a threshold. Permiso does not claim to evaluate a call before it runs, and it argues against prevention by guardrails.AML.T0103—If a developer's account that normally works on a specific project suddenly attempts privilege escalation or spawns unexpected sub-agents, the system flags the behavior immediately.
https://permiso.io/blog/8-critical-ai-security-challenges (read 2026-09-27)AML.T0007—Permiso inventories every AI agent, sub-agent, builder, model, and user across cloud, SaaS, IdPs, and code environments, including agents running in Lambdas, containers, and VMs that traditional identity tools cannot see.
https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0084—Permiso models AI identities explicitly: tracking which agents have access to which tools and data
https://permiso.io/resources/why-siem-isnt-enough-for-identity-security (read 2026-09-27)
Limit: An inventory of which tools and data each agent can reach. It does not detect an adversary who is enumerating agent configuration.AML.T0085—When an agent starts accessing production data it has never touched before, or connects to an MCP server outside its normal pattern, the kill switch stops the session before the blast radius expands.
https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
Limit: Keyed to first-time data access against the agent's own baseline, and answered at the identity layer. Permiso does not inspect what is retrieved.AML.T0048—We also detect suspicious and malicious activity in your LLM instances by monitoring your prompt logs to detect LLM hijacking quickly.
https://permiso.io/llm-hijacking-monitoring (read 2026-09-27)
Limit: Covers LLMjacking only, meaning unauthorised use of the customer's own hosted LLM instances. ATLAS's LLM Jacking case study (AML.CS0030) maps that to the financial-harm sub-technique. Harmful-content output is not addressed.
Above Security 2 of 76
Above Security sells an AI-native insider-risk platform: AI investigative agents that build cases for security, HR and legal teams from identity, SaaS, endpoint, cloud and AI-tool connectors, plus real-time coaching of employees. Its research group, Above Theory, co-authored the Synthetic Insider Threat Matrix with Forscie. It works after the fact and through APIs: its Claude integration reads Claude activity, including Claude Code session transcripts, hourly and read-only from Anthropic's Compliance API, and Above states that no enforcement action is taken autonomously on an AI verdict. A joint brief with CrowdStrike assigns stopping a hijacked agent at runtime to the endpoint product, not to Above. About 70 pages were read on 1 October 2026: the whole sitemap, with about 30 read in full, plus three first-party PDFs and its GitHub plugin. The customer portal and trust center are behind a login and were not read. Not credited: the Claude integration's tool-call records (AML.T0053), because recording every tool call is not detecting or stopping one; the prompt-injection screen in the same guide, which protects Above's own analysis rather than the customer's agents; the personal-AI, custom-GPT and credential-leak pages, which govern how employees use AI rather than an adversary's technique; and research write-ups, including the matrix itself.
AML.T0103—Above's investigative agents observe the consent screen, the scopes requested, and the vendor on the other end — so a grant to a vendor outside your approved list reaches the security team in minutes, not next quarter's access review.
https://www.above.security/agentic-ai (read 2026-10-01)
Limit: Visibility and alerting on OAuth consent grants to third-party AI agents, routed to the security team for an allow-or-revoke decision. Not prevention, and not agents launched on a device. Above says no enforcement action is taken autonomously on an AI verdict.AML.T0086—When an autonomous agent reproduces a confidential file on its vendor's servers, the investigation ties the reproduction back to the consent that enabled it — so the exfiltration is attributable to the employee, the agent, the consent, and the file, not to “an AI tool somewhere.”
https://www.above.security/agentic-ai (read 2026-10-01)
Limit: After-the-fact investigation and attribution of data that an OAuth-scoped third-party agent has already reproduced off-site. Above does not claim to intercept or evaluate the agent's tool calls.
Rig Security 2 of 76
Rig Security sells an identity security platform for people, non-human identities and AI agents: agentless connectors build one identity graph across systems such as Okta, GitHub, Snowflake, Google Cloud and Kubernetes, and a lightweight endpoint sensor, Gatewatch, enforces policy on devices before an agent's action runs. It came out of stealth on 29 September 2026. Its decisions are keyed to identity and resource, which agent is acting through whose session and what it may reach, and it publishes no claim to inspect prompts, files or tool arguments for content. The material is thin: two product pages, about a dozen blog posts and no public product documentation. 28 pages were read on 1 October 2026, plus its GitHub organisation. Not credited: the animated Gatewatch demo strings and labels marked illustrative, which are interface, not claims; an Entra ID screenshot caption about application access, which is identity posture; and its blog's prompt-injection scenario, which explains the attack rather than claiming to detect it.
AML.T0053—It can block a risky agent action before it reaches the cloud without disrupting the person whose identity the agent borrowed.
https://www.rig.security/blog-events/why-we-started-rig-end-to-end-identity-security-platform/ (read 2026-10-01)
Limit: Inline enforcement on endpoints running the Gatewatch sensor, keyed to which agent is acting and which identity or resource it reaches (Rig's examples are AWS production versus dev). Rig does not publicly describe inspecting prompts, files read or tool arguments for malicious content, and it publishes no product documentation.AML.T0103—It discovers agents running on devices, distinguishes their sessions from the user’s own activity, and enforces policy inline.
https://www.rig.security/blog-events/why-we-started-rig-end-to-end-identity-security-platform/ (read 2026-10-01)
Limit: Discovery and attribution of agents on devices where the Gatewatch sensor is deployed. This is inventory, not detection of an adversary launching an agent.
Noma Security 20 of 76
Noma Security sells an agent security platform across SaaS, homegrown and endpoint agents, including plugins that send coding-agent hook events (Claude Code, Codex, Cursor, Copilot) to its backend for evaluation. Read 2026-10-01 from noma.security product, solution and blog pages (server-rendered, read with curl). Noma documents the same native-hook path for Claude Code and Cursor that MoorAI uses, plus EDR/MDM-based endpoint discovery, so most coding-agent cells are first-party claims rather than inference. Several cells are posture or inventory findings and carry a limit. Not credited: the red-teaming list's denial-of-wallet (one sentence, one cell: it is credited to jailbreak only), 'agents drifting from their intent' (no matching technique), and research posts (ContextCrush, Cursor triple-backtick) that explain attacks. Noma states what it does not do in one place: 'Noma's job is not to scan your code for vulnerabilities.' Where hook-time content is evaluated (Noma SaaS or the customer's on-prem deployment) is not stated for the coding-agent path; the platform offers on-prem and SaaS. Product documentation is not public and was not read.
AML.T0018—Noma scans models from open registries for malicious artifacts, hidden instructions, and known vulnerabilities.
https://noma.security/solutions/ai-supply-chain-security (read 2026-10-01)AML.T0010—Each MCP server is assessed for AI-specific supply chain risks that code scanners don't cover
https://noma.security/solutions/mcp-security (read 2026-10-01)
Limit: A posture assessment of MCP servers (unpinned versions, permissions, low-trust packages, known vulnerabilities), not interception of a compromised package at install or run time.AML.T0132—Find risky mistakes and misconfiguration in AI agents like excessive agency, unsandboxed agents, secrets in agent instructions, unauthenticated access, and more.
https://noma.security/products/ai-spm (read 2026-10-01)
Limit: Posture finding, not runtime enforcement.AML.T0051—Detection covers prompt injection, sensitive data leakage, scope violations, and custom policies.
https://noma.security/solutions/coding-assistant-security (read 2026-10-01)AML.T0053—Define and enforce which agents can use specific skills and tools within an MCP, based on criteria like runtime context and the human the agent is attributed to.
https://noma.security/products/agent-access-control (read 2026-10-01)AML.T0103—It blocks the unauthorized and malicious ones, controls what each agent can do, and stops risky behavior in runtime.
https://noma.security/platform/endpoint-agents (read 2026-10-01)
Limit: Shadow-agent governance of endpoint agents, MCP servers and skills against an approved registry; not framed as detecting an adversary-deployed agent.AML.T0081—Every new agent, every configuration change, and every new MCP connection is detected as it appears.
https://noma.security/solutions/ai-asset-discovery (read 2026-10-01)
Limit: Detection of configuration change as an inventory event; Noma does not say it blocks or attributes the change.AML.T0099—Noma monitors tool call responses in real time and detects embedded prompt injection, exfiltration patterns, and cross-server shadowing before the agent acts on them.
https://noma.security/solutions/mcp-security (read 2026-10-01)AML.T0110—Scan, govern and monitor against a model with hidden instructions, an MCP server with modified tool descriptions or an unpinned package that silently pulls a compromised update on every invocation.
https://noma.security/products/ai-spm (read 2026-10-01)AML.T0054—Techniques include prompt injection, jailbreak, data leakage, denial-of-wallet, harmful content generation, and more.
https://noma.security/products/ai-red-teaming (read 2026-10-01)
Limit: From AI Red Teaming, which tests the customer's own apps and agents for jailbreaks rather than blocking them at runtime.AML.T0068—Detectors include prompt injection (including encoded and obfuscated payloads)
https://noma.security/products/ai-dr (read 2026-10-01)AML.T0109—including protection from tool poisoning, tool shadowing and rug-pulls
https://noma.security/blog/securing-the-agentic-frontier-noma-unveils-the-first-real-time-agent-runtime-security-for-cursor (read 2026-10-01)AML.T0007—Find every agent, MCP server, toolset, skill, and model, across all agent types: endpoint AI, SaaS, and homegrown.
https://noma.security/products/ai-spm (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0084—Noma turns that local state into a live inventory of agents, IDEs, MCP servers, skills, hooks, and connected accounts across managed devices.
https://noma.security/blog/noma-brings-agent-security-to-every-employee-endpoint (read 2026-10-01)
Limit: Inventory built from EDR or MDM telemetry; it does not detect an adversary enumerating agent configuration.AML.T0133—Noma discovers every MCP server across your organization: which servers are installed, which agents they connect to, which tools they expose, and how they're configured.
https://noma.security/solutions/mcp-security (read 2026-10-01)
Limit: Inventory of the defender's own MCP servers and tools, not detection of an agent being probed for its capabilities.AML.T0057—Noma detects sensitive data (credentials, PII, PCI, secrets, proprietary code patterns) and can mask it inline before it leaves the developer's environment.
https://noma.security/solutions/coding-assistant-security (read 2026-10-01)AML.T0086—Identify and block attempts to query sensitive data and report it to untrusted external sources.
https://noma.security/blog/securing-the-agentic-frontier-noma-unveils-the-first-real-time-agent-runtime-security-for-cursor (read 2026-10-01)AML.T0101—Classify and immediately halt destructive commands or tool calls that could alter or destroy your production environments.
https://noma.security/blog/securing-the-agentic-frontier-noma-unveils-the-first-real-time-agent-runtime-security-for-cursor (read 2026-10-01)AML.T0083—Noma detects connected personal-accounts, along with secrets in agent instructions, unsandboxed agents, and excessive agency.
https://noma.security/platform/endpoint-agents (read 2026-10-01)
Limit: A posture finding about secrets stored in agent instructions; it does not describe preventing an agent from reading them.AML.T0098—Block access to sensitive files like .env keys or configuration files, protecting your secrets.
https://noma.security/blog/securing-the-agentic-frontier-noma-unveils-the-first-real-time-agent-runtime-security-for-cursor (read 2026-10-01)
Limit: Stated in a December 2025 launch post about Cursor hooks; the Claude Code coverage page does not repeat the file-access claim.
Onyx Security 7 of 76
Onyx Security sells a secure AI control plane for agents across SaaS, cloud, endpoint and code, enforcing at coding-agent hooks, an MCP proxy and AI gateway, and Anthropic's inference hooks, and recording session content for investigation. Onyx Security (onyx.security, Tel Aviv / New York; $40M launch and a $113M Series B led by Bessemer per its own blog) - not Onyx the open-source enterprise-search product (onyx.app). Read 2026-10-01. Four solution pages linked from its navigation (MCP Security, Runtime and Prompt Injection Defense, AI Discovery and Shadow AI, Agent Identity and Access Governance) returned 404 and were not read. Several cells come from customer-success and POV blog posts describing what AI Guard did in deployments, including anonymised composite cases; these are bounded. Onyx states that it maps policy to MITRE ATLAS automatically, but publishes no per-technique mapping, so that statement earns nothing here. Its MCP post lists install-time posture inspection and toolset drift as things an MCP programme 'needs' without saying in that sentence that Onyx does it; not credited. Approval routing for newly discovered tools and MCP servers is read as governance and not credited. A post built around a third-party report was skipped, as third-party content. Unlike MoorAI, Onyx records prompt, response and tool-call content (session capture with arguments and results), and ingests Claude Enterprise conversation content through the Compliance API.
AML.T0051—Protect your AI systems and the data they touch from prompt injection, jailbreaks, data exfiltration, and adversarial manipulation in real time, without disrupting workflows.
https://www.onyx.security/platform (read 2026-10-01)AML.T0053—Specify the tools and MCP servers you trust, and block the rest.
https://www.onyx.security/platform/ai-governance (read 2026-10-01)AML.T0054—Red teaming continuously attacks deployed agents to surface what static reviews miss, generating attack plans across reconnaissance, jailbreaking, and weaponization.
https://www.onyx.security/platform/ai-security (read 2026-10-01)
Limit: Automated red teaming of deployed agents (testing). The runtime jailbreak claim on the platform page shares a sentence with the prompt-injection cell and is not counted twice.AML.T0057—PII, credentials, and confidential content detected in prompt or response are masked in transit.
https://www.onyx.security/blog/four-guardrails-the-customer-success-pattern-for-safe-ai-agent-adoption (read 2026-10-01)AML.T0086—Onyx blocked the tool call at the boundary, flagged the specific LLM reasoning that led to the action, and alerted the security team.
https://www.onyx.security/blog/tales-from-the-runtime-layer-why-authorized-agents-break-your-security-and-your-infrastructure (read 2026-10-01)
Limit: An anonymised scenario the post says is composited from POV work with several customers (a coding agent posting an AWS key to an external webhook after an injected README instruction).AML.T0101—An agent session that attempts a file delete, a database write outside its scope, or a shell command outside approved policy: AI Guard blocks the tool call before it executes and logs the attempt.
https://www.onyx.security/blog/four-guardrails-the-customer-success-pattern-for-safe-ai-agent-adoption (read 2026-10-01)
Limit: Policy-based blocking of destructive tool calls, framed by Onyx around agent mistakes rather than adversary-driven destruction.AML.T0083—Hardcoded secrets or API keys in instruction files or rule definitions
https://www.onyx.security/blog/four-guardrails-the-customer-success-pattern-for-safe-ai-agent-adoption (read 2026-10-01)
Limit: Posture scanning of agent configuration files for stored credentials, from a list of what Onyx's configuration reviews look for; it reduces what an adversary could harvest rather than detecting the harvesting.
Akto 21 of 76
Akto sells an agentic AI and API security platform whose endpoint connectors and hooks for coding agents such as Claude Code report to its dashboard. Read 2026-10-01: akto.io product pages (Framer; blog posts needed the browser), the public GitBook docs at ai-security-docs.akto.io (Atlas for employee endpoints, Agent Guard scanner reference, guardrail concepts), and pricing. Akto Atlas ships hooks for Claude Code, Cursor, Codex, Gemini, Copilot and others plus an MDM-deployed AI Endpoint Shield, so it competes directly on coding agents. Its Atlas Guardrails page says policies 'are evaluated locally on each device', but its Claude CLI hook docs send prompts and MCP tool calls to an Akto ingestion URL (SaaS by default, on-prem optional), and its pricing page offers a module that 'Logs every prompt, response, violation and skill call as a forensic audit trail'. Stated limits: in the Claude Code hooks, ingestion of non-MCP tool calls (Bash, Read, Edit) is off by default; the Personal Account guardrail works only through the browser extension, with Endpoint Shield support 'coming soon'; Agentic Shield for local LLM calls is 'coming soon'. A blanket pricing-page claim of 'Full coverage of OWASP Top 10 & MITRE ATLAS threats' was not credited because it names no technique. Red-team probe lists were not scored beyond the runtime cells.
AML.T0010—Stop supply-chain attacks, prompt injection, and data exfiltration.
https://www.akto.io/securing-agent-skills (read 2026-10-01)
Limit: Stated for agent skills (SKILL.md inventory and scanning) only.AML.T0011—Identifies suspicious, malicious, or inappropriate URLs in AI responses.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0051—At runtime, if an injected instruction surfaces during execution, the PromptInjection Guardrail in Agent Guard enforces blocking.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/ai-agent-activity/agentic-skills (read 2026-10-01)AML.T0053—Enforces allowlist or policy-based tool access
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0103—Shadow AI usage - enforce guardrails on AI tools and MCP servers that fall outside your approved list.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/atlas-guardrails (read 2026-10-01)
Limit: Shadow-AI governance against an approved list, not detection of an adversary launching an agent.AML.T0080—Detects and blocks attempts to poison agent memory, context, or conversation state.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0081—Use Create Misconfiguration Policies to pin a config field to an expected value.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/misconfigurations (read 2026-10-01)
Limit: Posture scan of Claude Code, Codex CLI and Copilot CLI config files found by the Endpoint Shield; it flags weakened settings rather than blocking the write.AML.T0099—Detects and blocks malicious or unsafe tool responses before they are used by the agent.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0110—Scans tool definitions and metadata for security risks
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0054—Unsafe prompts and jailbreaks - detect prompt injection, jailbreak patterns, and policy-violating instructions on the endpoint.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/atlas-guardrails (read 2026-10-01)AML.T0068—checking whether the prompt contains malicious patterns, such as prompt-injection attempts or encoded commands
https://www.akto.io/blog/introducing-akto-claude-code-security-guardrails-for-ai-powered-development (read 2026-10-01)
Limit: Stated for the Claude Code UserPromptSubmit hook, i.e. the user's prompt, not tool output.AML.T0084—Every connector feeds one continuously updated inventory, so you always know which agents, MCP servers, LLMs, skills, and plugins are in use, and on which endpoint, employee, and device.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/overview (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.AML.T0133—Context-maps each agent to the MCP servers, tools and databases it connects to
https://www.akto.io/pricing (read 2026-10-01)
Limit: Inventory of the defender's own agents' reach, not detection of capability probing.AML.T0056—System prompt extraction requests
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)
Limit: A listed catch of the PromptInjection guardrail rather than a separate detector.AML.T0057—Detects personally identifiable information (PII) and sensitive data in AI outputs.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)AML.T0086—Prevents agents from communicating with unauthorised external services, competitor platforms, or known data-exfiltration endpoints.
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)
Limit: A host and path blocklist with wildcards; it does not inspect what the request carries.AML.T0029—Abuse prevention (spam, flooding)
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)
Limit: A use case of the Behavioural Anomaly guardrail (request-rate and repetition baselines), not a dedicated denial-of-service control.AML.T0048—Enterprise license compliance - block prompts and responses that would breach your LLM provider's acceptable-use policy (CSAM, weapons, terrorism, hate speech, and more), protecting your organization's enterprise license.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/atlas-guardrails (read 2026-10-01)
Limit: Framed as protecting the customer's LLM licence standing rather than as stopping misuse by an adversary.AML.T0101—Risky MCP tool calls - restrict destructive shell commands, file system access, and unvetted MCP tools from executing on the device.
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/atlas-guardrails (read 2026-10-01)AML.T0083—hardcoded credentials and sensitive identifiers in skill content
https://ai-security-docs.akto.io/akto-atlas-agentic-ai-security-for-employee-endpoints/ai-agent-activity/agentic-skills (read 2026-10-01)
Limit: A risk-scoring finding about credentials stored in skill files, not prevention of an agent reading them.AML.T0098—Scans tool responses for sensitive data exposure
https://ai-security-docs.akto.io/agentic-guardrails/concepts/agent-guard (read 2026-10-01)
Limit: Output-side scan of what a tool returns; the documented example is an API key in a file-reader response.
HiddenLayer 14 of 76
HiddenLayer sells an AI security platform for models, supply chain, red teaming and runtime, including Agent Harness Security, a hook plug-in for coding agents such as Claude Code, Cursor and GitHub Copilot that calls its detection API. Read 2026-10-01: hiddenlayer.com platform and solution pages, the Agent Harness Security launch release (3 August 2026) and Series B release (2 September 2026), and the public docs at docs.hiddenlayer.ai (Agent Harness architecture, deployment and policy; Agentic Runtime Security; data handling). Agent Harness Security is a direct competitor on coding agents: a plug-in installs hooks for Claude Code, Cursor and Copilot CLI that call HiddenLayer's detection API (/detection/v2/claude-code/ and siblings). Its data-handling doc says Enterprise SaaS sends 'Detection data, including prompts and responses' through the API, while Hybrid can keep prompts and responses local and Self-Hosted sends nothing out. Stated limits: 'Not every gate point can enforce every action'; post-action gates are visibility only; Copilot CLI prompt submission is visibility only; Agentic Runtime Security 'may not be enabled for your tenant yet'. Not credited: model genealogy and 'detect corruption across layers and tensors' (integrity checking, not clearly AML.T0076), and 'Model Exfiltration & Data Leakage Testing', whose sentence describes probing for PII extraction rather than model theft.
AML.T0018—Identify malicious code inside model files that may serve as infection vectors.
https://www.hiddenlayer.com/solutions/model-scanning (read 2026-10-01)AML.T0011—Detect prompt injection embedded in source files and tool outputs, secrets flowing into AI tool calls, unsafe command execution, malicious or unexpected dependency installs, and obfuscated payloads designed to evade review.
https://www.hiddenlayer.com/news/hiddenlayer-unveils-agent-harness-security (read 2026-10-01)
Limit: Credited for the dependency-install clause only; the detection mechanism for malicious packages is not described.AML.T0051—Detect and block indirect prompt injection before it influences agent behavior.
https://www.hiddenlayer.com/solutions/agent-harness-security (read 2026-10-01)AML.T0053—Monitor agent actions and enforce runtime policy across APIs, MCP tools, code execution, communication tools, and filesystem operations.
https://www.hiddenlayer.com/solutions/agentic-mcp-security (read 2026-10-01)AML.T0103—Surface unofficial models, agents, and API integrations.
https://www.hiddenlayer.com/platform/ai-discovery (read 2026-10-01)
Limit: Shadow-AI discovery, not detection of an adversary launching an agent.AML.T0080—Detect unsafe memory recall, cross agent contamination, and exposed sensitive data before it becomes an instruction.
https://www.hiddenlayer.com/solutions/agentic-mcp-security (read 2026-10-01)AML.T0099—Identify and block prompt injection hidden inside data, documents, MCP responses, or retrieved context before it impacts agent execution.
https://www.hiddenlayer.com/solutions/agentic-mcp-security (read 2026-10-01)AML.T0054—Test for jailbreaks, injection, role confusion, and harmful response patterns.
https://www.hiddenlayer.com/platform/ai-attack-simulation (read 2026-10-01)
Limit: From AI Attack Simulation, which tests for jailbreaks rather than blocking them at runtime.AML.T0068—Full Scan - Scans the full input and performs a second scan with non-alphanumeric characters stripped.
https://docs.hiddenlayer.ai/docs/products/runtime/agent_harness/policy (read 2026-10-01)AML.T0007—Scan cloud accounts, repos, endpoints, and pipelines to detect every model and associated agent.
https://www.hiddenlayer.com/platform/ai-discovery (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0056—Identify prompt weaknesses causing leakage or override.
https://www.hiddenlayer.com/platform/ai-attack-simulation (read 2026-10-01)
Limit: System prompt hardening in attack simulation; a test, not runtime prevention.AML.T0057—Detect and prevent PII, PHI, and proprietary data exposure in generated content.
https://www.hiddenlayer.com/solutions/ai-guardrails (read 2026-10-01)AML.T0077—URLs: links that may be used for data exfiltration or phishing.
https://docs.hiddenlayer.ai/docs/products/runtime/agentic/overview (read 2026-10-01)
Limit: A URL detection outcome in Agentic Runtime Security; HiddenLayer does not say it checks whether the link carries conversation data.AML.T0029—Denial of Service - Detects an attempt to overload model traffic to degrade performance or consume tokens.
https://docs.hiddenlayer.ai/docs/products/runtime/agent_harness/policy (read 2026-10-01)
Limit: A per-requester token threshold (default 4096 tokens).
Virtue AI 6 of 76
Virtue AI sells a multimodal agent-security suite whose AgentSuite-Blue reaches desktop agents such as Claude Code and GitHub Copilot through hooks or its gateway. Virtue AI was acquired by Fortinet (Fortinet press release, 17 August 2026; terms not disclosed, 'immaterial to Fortinet's business'). Read 2026-10-01 from virtueai.com, docs.virtueai.com (JavaScript-rendered; read in a browser) and Fortinet's release. The AgentSuite-Blue docs state that it protects desktop agents 'e.g., Claude Code, GitHub Copilot, AMP agents' via hooks or its gateway. One cell (prompt injection) comes from the AgentSuite-Red red-teaming page and describes testing only; the runtime Prompt Guard is described in the docs only as detecting 'potentially malicious prompts', which does not name the technique. The sensitive-data cell is from Fortinet's own release describing the acquired guardrails. The release also credits FortiAIGate (a separate, pre-existing Fortinet product) with prompt-injection, data-leakage, model-poisoning and resource-consumption defences; those are not credited to Virtue. Shadow AI (endpoint discovery and session trajectory reconstruction, EDR integration) was read as governance and not credited. Third-party report content quoted on the Virtue site and in the Fortinet release was not used.
AML.T0051—An adversarial red-teaming agent equipped with diverse red teaming algorithms probes your agents under both direct and indirect prompt-injection threat models, drawing on a library of reusable attack skills.
https://www.virtueai.com/agentsuite-red (read 2026-10-01)
Limit: Red-team testing (AgentSuite-Red), not a runtime prompt-injection control.AML.T0053—It can detect potentially malicious tool calls based on the agent execution history and block the malicious tool calls before they are executed.
https://docs.virtueai.com/virtueagent/ (read 2026-10-01)AML.T0081—Skill Guard statically scans agent skills, analyzing their contents to detect malicious instructions and injected prompts before the skill is loaded by an agent.
https://docs.virtueai.com/virtueagent/ (read 2026-10-01)AML.T0110—For connected MCPs and APIs, MCP Guard statically scans the tool descriptions of all the tools and detects the tools with injected prompts.
https://docs.virtueai.com/virtueagent/ (read 2026-10-01)
Limit: Static scan of tool descriptions (definition), plus optional code scanning for vulnerabilities; not a runtime check of tool responses.AML.T0054—Fast text guardrail covering violence, hate, PII exposure, jailbreaks, and 12+ harm categories in 100+ languages.
https://www.virtueai.com/virtueguard (read 2026-10-01)AML.T0057—Enforces customizable policies across text, images, video, audio, and AI-generated code to prevent harmful content, sensitive data, jailbreaks, and vulnerable code from reaching users or downstream systems.
https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2026/fortinet-advances-continuous-ai-protection-with-the-acquisition-of-virtue-ai (read 2026-10-01)
Limit: Fortinet's description of Virtue AI's real-time guardrails in its acquisition release; the jailbreak claim in this sentence is not counted again.
NeuralTrust 19 of 76
NeuralTrust sells a gateway-first agent security platform with hook plugins for coding agents that send each event to its TrustGuard evaluator. Read 1 October 2026: about 310 English pages of neuraltrust.ai (product pages, 239 blog posts, news, guides, llms.txt and llms-full.txt) plus the README of the NeuralTrust GitHub plugins for Claude Code and Gemini CLI. The Spanish mirror and the 100+ glossary entries were not scored. docs.neuraltrust.ai was not read. Attack-family names listed on the threat-detection and red-teaming pages without a sentence (Obfuscation & Token Smuggling, PDF Metadata Injection and so on) were not scored as cells. The model performance report states its own limits: the benchmark was built to NeuralTrust's taxonomies (a home-field advantage it acknowledges), the indirect-injection model was scored only on an English held-out split of its own corpus, and browser-agent page injections are its weakest slice. NeuralTrust's comparison post states that it needs no endpoint agent and enforces at the traffic layer, although its GitHub publishes hook plugins for Claude Code, Codex, Cursor and Gemini CLI that send each event to a TrustGuard evaluate endpoint. Echo Chamber and Semantic Chaining are NeuralTrust attack research; the research itself was not scored. Its model scanner earns one cell, AML.T0018; the same page's supply-chain sentence describes the same scanner and is not counted again under AML.T0010.
AML.T0018—Detect corrupted models, poisoned tensors, and unsafe serialization artifacts that signal hidden threats.
https://neuraltrust.ai/model-scanner (read 2026-10-01)AML.T0118—Secure collaboration between multiple AI agents with identity verification and trust medication.
https://neuraltrust.ai/guardian-agent (read 2026-10-01)AML.T0132—Review MCP manifests and access definitions for insecure defaults, missing authentication, or overly broad permissions that violate least-privilege principles.
https://neuraltrust.ai/mcp-scanner (read 2026-10-01)
Limit: A posture finding from a scan, not runtime enforcement.AML.T0051—Prompt Guard detects and blocks injection attacks in real time, using multi-layered analysis and the industry’s most extensive jailbreak database.
https://neuraltrust.ai/prompt-guard (read 2026-10-01)AML.T0053—Prevent unauthorized tool invocation and protect sensitive resources.
https://neuraltrust.ai/mcp-gateway (read 2026-10-01)AML.T0103—TrustLens surfaces every agent your employees interact with
https://neuraltrust.ai/agent-posture-management (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary-deployed agent.AML.T0099—Prompt injection, poisoned tool results, and rogue agent calls arrive as plain language. TrustGuard enforces before they reach your system.
https://neuraltrust.ai/ai-agent-security (read 2026-10-01)
Limit: NeuralTrust's model report evaluates its indirect-injection model on an English-only held-out split of its own training corpus, and names browser-agent page injections as the weakest slice.AML.T0110—Detect poisoned or redefined tools, insecure MCP servers, and unsafe endpoint exposures that could compromise trust boundaries.
https://neuraltrust.ai/mcp-scanner (read 2026-10-01)
Limit: A scan of MCP server code and configuration, not runtime enforcement.AML.T0054—TrustGuard tracks conversation context across turns — catching multi-turn attacks where a jailbreak fails once and succeeds on the third attempt.
https://neuraltrust.ai/ai-agent-security (read 2026-10-01)
Limit: Enforced where traffic reaches a NeuralTrust collector (gateway, SDK, browser, sidecar or log stream).AML.T0068—Protect your LLM applications from jailbreaks, obfuscations, and malicious inputs
https://neuraltrust.ai/prompt-guard (read 2026-10-01)
Limit: NeuralTrust's own model report names inline-encoded payloads (base64/hex/ROT13) as the toxicity model's one material robustness gap.AML.T0129—Detect and block hidden jailbreaks embedded in images, audio, or non-text inputs before they execute.
https://neuraltrust.ai/prompt-guard (read 2026-10-01)AML.T0084—TrustLens discovers every agent in your enterprise, tracks what they're configured to do, and records what they actually do
https://neuraltrust.ai/agent-posture-management (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.AML.T0056—The most common attack families (instruction overrides and system-prompt extraction) are detected at 99%.
https://neuraltrust.ai/blog/neuraltrust-ai-security-model-performance-report-2026 (read 2026-10-01)
Limit: A detection rate on NeuralTrust's own benchmark, which the report says was built to its own taxonomies and carries a home-field advantage.AML.T0057—Automatically detect and redact PII, credentials, and financial information in LLM prompts and responses
https://neuraltrust.ai/data-masking (read 2026-10-01)AML.T0086—Identify jailbreaks, prompt injections, and data exfiltration instantly.
https://neuraltrust.ai/guardian-agent (read 2026-10-01)
Limit: Stated as identification within agent tracing; the sentence does not say the exfiltrating call is blocked.AML.T0029—Block L3/L4 and L7 DDoS attacks in real time across your LLM applications.
https://neuraltrust.ai/bot-detection (read 2026-10-01)AML.T0034—Prevent unexpected expenses by limiting misuse, optimizing usage, and tracking spend.
https://neuraltrust.ai/bot-detection (read 2026-10-01)AML.T0048—Define and apply custom moderation rules to your LLM applications filtering unsafe, off-topic, or policy-violating content.
https://neuraltrust.ai/moderation (read 2026-10-01)AML.T0101—inspects prompts, tool calls and responses in real time to block injection, data leakage and destructive commands before they run.
https://neuraltrust.ai/blog/claude-code-vs-cursor-benchmark (read 2026-10-01)
DeepKeep 9 of 76
DeepKeep sells an AI security suite (firewall, model scanning, red teaming) whose AI Lens for Developers hooks Cursor and Claude Code and routes events to DeepKeep for a decision. Read 1 October 2026: all 64 pages in deepkeep.ai's sitemap (capability and use-case pages, 25 blog posts, press). DeepKeep's own blog argues that jailbreaks cannot be reliably detected and recommends containment, so its jailbreak cell carries that limit. Its InkJect research shows visual prompt injection defeating text guardrails on four models and closes by saying the gap remains open until defenses work at the visual layer; it does not claim DeepKeep blocks it, so no multimodal-trigger cell was credited. AI Lens for Developers hooks into Cursor and Claude Code only today, sends each event to DeepKeep for a decision, and records an audit log that includes prompt content. Red-teaming categories listed on the red-teaming page were not scored separately from the runtime cells.
AML.T0018—Detect embedded malware, known vulnerabilities in model dependencies, signs of tampering, and unexpected behavior triggered by edge-case inputs.
https://www.deepkeep.ai/capabilities/model-scanning (read 2026-10-01)AML.T0051—It protects against AI-specific risks including prompt injection, jailbreak attempts, personal and sensitive data exposure, misuse of tools, and generation of harmful, biased, hallucinated, off-topic or non-compliant outputs.
https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)AML.T0053—These hooks provide checkpoints around prompts, shell commands, file reads, and MCP tool calls, routing activity to DeepKeep for an allow, block, or audit decision.
https://www.deepkeep.ai/blog/you-hired-a-brilliant-coding-agent-who-supervises-it (read 2026-10-01)
Limit: Cursor and Claude Code only today; GitHub Copilot, OpenAI Codex, Lovable and Windsurf are planned.AML.T0054—It monitors and controls prompts and responses to prevent risks such as data leakage, prompt injection, jailbreaks, and unsafe outputs.
https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)
Limit: DeepKeep's own blog says you can't reliably detect every jailbreak and recommends containment over detection.AML.T0084—AI Agent Scanner maps your agent's attack surface - tools, permissions, and orchestration paths - to reveal exploitable weaknesses
https://www.deepkeep.ai/capabilities/ai-agent-scanner (read 2026-10-01)
Limit: A design-time assessment of the customer's own agent, not runtime enforcement.AML.T0057—The AI Firewall prevents both external leakage and internal exposure between teams, ensuring that personal data is not shared across unintended boundaries.
https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)AML.T0048—Detects and removes toxic, offensive, harmful, unfair, unethical, or discriminatory language
https://www.deepkeep.ai/llm (read 2026-10-01)AML.T0101—It can also flag destructive shell commands and send them to the developer for approval before they run.
https://www.deepkeep.ai/blog/you-hired-a-brilliant-coding-agent-who-supervises-it (read 2026-10-01)
Limit: Sends the command for developer approval rather than blocking it outright; Cursor and Claude Code only today.AML.T0098—Detect credentials, tokens, and passwords in the information an agent receives and sends, including content the developer never typed into a prompt.
https://www.deepkeep.ai/capabilities/ai-lens (read 2026-10-01)
Limit: AI Lens for Developers supports Cursor and Claude Code today; other coding agents are planned.
Enkrypt AI 20 of 76
Enkrypt AI, now part of Anaconda, sells red teaming and runtime guardrails, with an open-source MCP gateway, a skill scanner and an OpenClaw plugin. Read 1 October 2026: about 330 pages of enkryptai.com (product and solution pages, 148 blog posts, newsroom, ClawPatrol), Anaconda's acquisition press release and blog (Anaconda acquired Enkrypt AI on 4 August 2026 and states existing products, plans and support are unchanged), and the enkryptai GitHub repositories skill-sentinel and secure-mcp-gateway, which are listed but whose code was not reviewed. The 180 glossary entries were not scored. Blog explainers of MCP attack classes (rug pulls, tool shadowing, schema poisoning) list defenses in general terms and were not scored as product claims. Bounds Enkrypt states: guardrails process inputs of up to 14,000 characters; ClawPatrol is an OpenClaw plugin; the MCP Scanner is pre-deployment and periodic, and the Gateway enforces only where MCP traffic is routed through it.
AML.T0118—Enkrypt AI monitors agent-to-agent handoffs and tool calls to catch data exposure before harvest happens.
https://www.enkryptai.com/blog/ai-agents-harvest-now-decrypt-later (read 2026-10-01)AML.T0010—untrusted MCP servers/tools and poisoned tool catalogs are treated as supply-chain risk, with allowlist/denylist guidance.
https://www.enkryptai.com/product/mcp-scanner (read 2026-10-01)
Limit: A scan with allowlist/denylist recommendations, not a runtime block.AML.T0011—Open-source scanner that treats Skills as the security-critical supply chain components they are.
https://www.enkryptai.com/solutions/secure-vibe-coding (read 2026-10-01)
Limit: Skill Sentinel is a pre-execution scanner run locally or in CI.AML.T0051—Enkrypt AI Guardrails provides real-time detection of injection attacks with minimal latency.
https://www.enkryptai.com/blog/enkrypt-ai-guardrails (read 2026-10-01)
Limit: Enkrypt states its guardrails process inputs of up to 14,000 characters.AML.T0053—Enkrypt AI Guardrails is the runtime layer that approves, modifies, or blocks risky behavior across agents, tools, RAG, and MCP - with decisions you can audit.
https://www.enkryptai.com/product/agent-guardrails (read 2026-10-01)AML.T0070—Enkrypt AI detects and blocks prompt injections before they compromise your RAG pipeline.
https://www.enkryptai.com/blog/build-secure-rag-workflows-with-mongodb-atlas-vector-search (read 2026-10-01)AML.T0081—Continuously monitors the cognitive workspace files that define who the agent is
https://www.enkryptai.com/clawpatrol (read 2026-10-01)
Limit: ClawPatrol is an OpenClaw plugin; files are re-hashed every 60 seconds and changed content is sent to the Enkrypt API for a verdict.AML.T0099—Validate tool responses to stop response smuggling back into the agent loop
https://www.enkryptai.com/product/mcp-gateway (read 2026-10-01)AML.T0110—Enkrypt AI's MCP Gateway stops prompt injection and tool poisoning before they reach your agents.
https://www.enkryptai.com/blog/securing-mcps-the-hidden-vulnerabilities-of-mcp-servers-and-a-gateway-to-safety (read 2026-10-01)
Limit: Inline only where MCP traffic is routed through the gateway.AML.T0054—runtime guardrails that block jailbreaks and sensitive-data leakage in real time
https://www.enkryptai.com/blog/anaconda-acquires-enkrypt-ai (read 2026-10-01)AML.T0109—Composite SHA-256 detects new/modified skills
https://www.enkryptai.com/clawpatrol (read 2026-10-01)
Limit: ClawPatrol, an OpenClaw plugin; a modified skill is re-scanned and alerted on, not blocked.AML.T0129—Enkrypt AI's multimodal red teaming capabilities detect image-based prompt injections before they bypass your defenses.
https://www.enkryptai.com/blog/a-not-so-brief-intro-to-vision-language-red-teaming (read 2026-10-01)
Limit: From red teaming, which probes for this rather than enforcing against it at runtime.AML.T0084—Enkrypt AI MCP Scanner discovers tools, analyzes capabilities and permissions, and surfaces high-risk exposure
https://www.enkryptai.com/product/mcp-scanner (read 2026-10-01)
Limit: A pre-deployment and periodic scan of MCP servers, not runtime enforcement.AML.T0056—Enkrypt AI Guardrails actively monitors interactions to detect and block attempts to extract system prompts
https://www.enkryptai.com/blog/enkrypt-ai-vs-azure-content-safety-vs-amazon-bedrock-guardrails (read 2026-10-01)AML.T0057—Redact sensitive data before it's sent to the model or logged in agent output
https://www.enkryptai.com/solutions/secure-vibe-coding (read 2026-10-01)AML.T0086—Block or alert on outbound network calls from coding agents to unknown endpoints
https://www.enkryptai.com/solutions/secure-vibe-coding (read 2026-10-01)AML.T0029—Apply sponge detection logic to automatically block excessive or looping inputs at runtime
https://www.enkryptai.com/blog/defending-against-sponge-attacks-in-genai-applications (read 2026-10-01)AML.T0048—Enkrypt AI Guardrails provide an additional layer of security, preventing harmful outputs in real time.
https://www.enkryptai.com/blog/automated-red-teaming-for-generative-ai-strengthening-ai-security-at-scale (read 2026-10-01)AML.T0112—Block dangerous shell commands, package installs, and system modifications at runtime
https://www.enkryptai.com/solutions/secure-vibe-coding (read 2026-10-01)AML.T0098—Prevent reading SSH keys, env files, cloud credentials, and API tokens without approval
https://www.enkryptai.com/solutions/secure-vibe-coding (read 2026-10-01)
Holistic AI 12 of 76
Holistic AI sells an AI governance platform (inventory, testing, compliance) with an SDK and a device agent, Endlayer, for runtime control. Read 1 October 2026: about 440 pages of holisticai.com (product, solution, blog, news, press, learn) plus the open-source holistic-ai/surface README. Several product pages (protect, identify, ai-red-teaming, testing-suite) render their copy from embedded Webflow code-island props rather than server HTML; that text was read from the props. Most of the site is AI governance (inventory, bias testing, EU AI Act/NIST/ISO workflows); per the method, governance of AI usage is not counted as adversary coverage, and red-teaming of third-party models (Grok, DeepSeek, Claude jailbreak audits) is research, not a product claim. The agent-runtime cells come from one product announcement (Runtime Agentic Enforcement via the HAI Guardian SDK, which must be integrated into the agent) and from the Endlayer device-agent page. Endlayer states its device tiers run no language model and that decrypted text never leaves the device. Holistic's own comparison page carries the line 'Rows marked ⚠ require internal confirmation before publishing', so nothing was scored from it. No claims were found for MCP tool poisoning, rug pulls, system-prompt extraction, RAG poisoning or hallucinated packages.
AML.T0118—It sees one agent call another, an agent reach an MCP server, or a tool ask for a permission it was never granted
https://www.holisticai.com/endlayer (read 2026-10-01)
Limit: Endlayer's Guardian tier, one of three device-agent tiers; the page gives no mechanism detail for agent-to-agent interception.AML.T0051—Detects manipulation attempts through injected instructions
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)
Limit: Enforced through the HAI Guardian SDK, which the customer integrates into the agent or application so its traffic routes through Holistic's monitoring pipeline.AML.T0053—Allowed Tools: an allowlist of tools the agent can use. Anything not on the list gets blocked by default.
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)
Limit: Requires the HAI Guardian SDK in the agent's path; Holistic lists Claude Code among the supported SDKs.AML.T0103—Every AI app, coding agent, local model, MCP server, account, credential and AI site appears on its own
https://www.holisticai.com/endlayer (read 2026-10-01)
Limit: Inventory and discovery on managed devices rather than enforcement against an adversary-deployed agent; seventeen tools are recognised by name, others surface as unidentified AI processes.AML.T0054—Advanced AI security mechanisms that detect and mitigate jailbreak attempts in real-time
https://www.holisticai.com/news/the-key-to-achieving-speed-and-security (read 2026-10-01)AML.T0007—Continuously discover and inventory every model, agent, API, and pipeline across cloud, code, and vendors
https://www.holisticai.com/ai-governance-platform (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0085—Customer PII: enforce data access policies at the resource level
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)AML.T0057—Detects and masks API keys, credentials, and PII in agent outputs
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)AML.T0034—when a session starts burning tokens at a rate that could impact other systems sharing the same quota, the monitoring layer cuts that session automatically
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)
Limit: Framed as cost control; Holistic states its cost figures are estimates from observed token counts against published pricing.AML.T0048—Blocks toxic, harmful, or inappropriate content
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)AML.T0101—rm -rf / is the obvious one. If an agent with terminal access tries to execute it, the call never reaches the shell.
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)AML.T0098—Environment variables: block access to secrets and credentials
https://www.holisticai.com/blog/runtime-agentic-monitoring-tools-access-control-cost (read 2026-10-01)
Airia 12 of 76
Airia sells an AI orchestration and governance platform whose control point is a cloud AI and MCP gateway, with browser and endpoint helpers. Read 1 October 2026: the 24 airia.com/ai-platform pages, about 390 blog and news posts, llms.txt, and the public pages of the airia.ai/docs site (Securing Claude, AI Gateway, MCP Gateway, Tool Scanning, Radar, Skills over MCP, discovery connectors). Ten docs pages redirected to a login (Claude Inference Hooks, Filters, Agent Constraints, Red Teaming, Gateway Rules, Gateway Traffic Anomaly Detection, Endpoint Agent overview, SASE Integration, Copilot Studio threat detection, MCP Monitoring) and were not read. Airia's docs state limits plainly and they are recorded here: MCP Tool Scanning is informational, not a gate; the browser extension is domain-scoped and not pre-submit keystroke DLP; agent constraints apply at the gateway and Bash commands that Claude Code runs locally never traverse it; native and mobile Claude apps are monitored after the fact, which it calls observation, not prevention. Most of Airia's site is orchestration, model routing and governance workflow, which was not scored. The 444 integration pages were not read. Its prompt-injection cell rests on the guardrails sentence that also earns the jailbreak cell, a list naming both; the Claude guide's statement that every prompt, completion and tool call passes through Airia describes routing, not detection, and earns nothing on its own.
AML.T0051—Block prompt injection, jailbreak attempts, and manipulation patterns before they reach the model.
https://airia.com/ai-platform/guardrails (read 2026-10-01)
Limit: Traffic routed through the Airia AI Gateway only; Airia's Claude guide says Claude iOS, Android and unlocked Desktop chat cannot be proxied and are monitored after the fact.AML.T0053—Control which tools agents can invoke and restrict the conditions under which they can act.
https://airia.com/ai-platform/agent-constraints (read 2026-10-01)
Limit: Airia's Claude guide states that agent constraints intercept tool calls at the gateway, and that Bash commands Claude Code runs locally never traverse it.AML.T0103—Airia identifies AI agents, LLM API calls, and MCP servers wherever they operate, then records them in a centralized inventory your team can govern.
https://airia.com/ai-platform/ai-discovery (read 2026-10-01)
Limit: Inventory and discovery rather than detection of an adversary-deployed agent.AML.T0110—Tool Scanning checks the tools exposed by connected MCP servers for hidden prompt injection attempts.
https://airia.ai/docs/mcp-servers/admin-controls/tool-scanning (read 2026-10-01)
Limit: Airia states Tool Scanning is informational, not a gate: it flags suspicious tool definitions and does not block them.AML.T0054—Block prompt injection, jailbreak attempts, and manipulation patterns before they reach the model.
https://airia.com/ai-platform/guardrails (read 2026-10-01)AML.T0109—Tool names and definitions are locked to those admin create and update events, so no new injection vector can appear later even if the underlying MCP is compromised.
https://airia.ai/docs/mcp-servers/admin-controls/tool-scanning (read 2026-10-01)
Limit: Applies to tools served through an Airia MCP Gateway or Deployment.AML.T0084—The agent inventories the MCP servers and LLM clients configured on each device and reports them
https://airia.ai/docs/secure/securing-claude (read 2026-10-01)
Limit: Observe mode of the airiad endpoint agent; Airia's guide lists macOS Apple Silicon as the packaged platform today.AML.T0056—multi-step attack chains that combine jailbreaks, prompt extraction, and exfiltration attempts
https://airia.com/blog/ai-jailbreaks-system-prompt-leakage-and-data-exfiltration-how-to-red-team-for-all-three (read 2026-10-01)
Limit: From red teaming, which probes for this rather than enforcing against it at runtime.AML.T0057—Automatically detect and mask regulated data to prevent unintended exposure across AI workflows.
https://airia.com/ai-platform/guardrails (read 2026-10-01)AML.T0086—these controls ensure that even a compromised agent cannot send data to unauthorized destinations or include sensitive information in outbound communications.
https://airia.com/blog/ai-jailbreaks-system-prompt-leakage-and-data-exfiltration-how-to-red-team-for-all-three (read 2026-10-01)AML.T0034—Live loop detection that catches runaway agents and spending spikes in real time
https://airia.com/blog/airia-announces-enhanced-cost-optimization-to-give-enterprises-real-time-control-over-ai-spend (read 2026-10-01)AML.T0048—Inspect responses for sensitive data, bias, and toxicity before they leave the platform.
https://airia.com/ai-platform/guardrails (read 2026-10-01)
Aurascape 11 of 76
Aurascape sells an inline AI traffic proxy and MCP gateway, steered alongside an existing SASE stack, that covers coding assistants from the network side. Read 2026-10-01 from aurascape.ai solution pages, product page, FAQs, two blog posts, a case study and the MCP gateway data-sheet summary (the PDFs behind 'Solution Brief PDF' and the data sheet were not downloaded). Aurascape inspects AI traffic inline as a proxy steered alongside an existing SASE stack, decoding SSE, WebSockets, gRPC, Protobuf and MCP, plus a 'Zero-Bypass' MCP gateway; coding-agent coverage is network-side, not a hook on the device. Its own pages bound MCP enforcement to 'supported paths' and 'gateway-routed' tool calls, and tool-poisoning blocking to 'governed deployments'. It keeps full conversation logs for security operations. Aura Labs research posts (ChatGPT Agent Mode, SilentBridge, DNS tunnelling, LLM search poisoning) explain attacks and were not credited. Not credited: secret redaction for prompts as a credential-harvesting cell (it is credited once, as data leakage). Not credited: a sentence on blocking a typosquatted package returned to a coding assistant, considered for AML.T0060 Publish Hallucinated Entities; a typosquatted name is not a hallucinated one, and the sentence does not name hallucination.
AML.T0011—Detect embedded threats in real time across generated responses, including links, attachments, or agent-initiated actions.
https://aurascape.ai/product/ (read 2026-10-01)AML.T0051—A hijacked instruction hidden in a README or a connected document, telling the agent to post secrets to an external site, is detected and neutralized.
https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)AML.T0053—Allow marked, approved tools, and block unsanctioned tool calls routed through the gateway.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
Limit: Gateway-routed tool calls only; Aurascape says a call that skips the gateway is caught through the model conversation instead.AML.T0103—Find employee-used agents, agents embedded in SaaS, internally built agents, and shadow MCP servers connected without IT oversight.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
Limit: Shadow-agent discovery, not detection of an adversary launching an agent.AML.T0110—In governed deployments, Aurascape inspects that exchange and blocks the poisoned tool and the resulting connection before data leaves.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
Limit: Bounded by Aurascape itself to governed deployments.AML.T0054—Runtime guardrails provide prompt-injection and jailbreak detection, PII filtering, credential guard, code-injection checks, and output sanitization.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
Limit: Applied on the model-conversation channel through the AI Proxy.AML.T0133—It maintains a catalog of registered servers with their tools, a risk score, and a security scan, and it flags tools it finds operating outside the gateway.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
Limit: Inventory of the defender's MCP servers and tools.AML.T0057—Redact keys, tokens, and credentials in flight before an assistant or an unapproved model ever receives them.
https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)AML.T0086—Follow data across chained tool calls and flag when it crosses a trust boundary.
https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)AML.T0048—Analyze every AI prompt and response to detect risks like phishing, social engineering, and malicious code generation—before they reach the user.
https://aurascape.ai/product/ (read 2026-10-01)AML.T0101—Stop destructive or exploitative commands and runtimes before they reach the shell, caught by policy rather than left to a developer to notice in time.
https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)
Limit: Caught in the tool call the model streams back over the network, before the client executes it, so it depends on traffic being steered through Aurascape.
Cranium 10 of 76
Cranium sells an AI governance and assurance platform: AI inventory from code and cloud, red teaming, and a static scanner for agent configuration files. Read 2026-10-01: cranium.ai platform and solution pages, Cranium press releases (Series A, Arena launch, Aiceberg acquisition, coding-assistant vulnerability) and the public knowledge base at docs.cranium.ai. Cranium is a governance-first platform (discovery, AI-BOM, compliance, AI Cards) with red teaming (Arena) and, since acquiring Aiceberg in May 2026, an inline or listen-mode guardrail engine (Guardian) that sits between an AI tool and its LLM. The coding-agent cells come from the Adversarial Inputs Detector, a static scanner of rules and command files that Cranium released as free IDE plugins after its February 2026 coding-assistant research; the download link in that press release now redirects to /platform/secure/ and no repository was found, so the plugin itself was not read. Cranium states one boundary in its FAQ: asked whether it prevents users sending sensitive data to ChatGPT, it answers 'No, our tooling focuses on the internal systems of organizations and their vendors.' Arena attack categories (harmful responses, misinformation, hallucinations, encoding attacks, cyberattacks) were not credited beyond the cells below.
AML.T0051—Identify and mitigate prompt injection vulnerabilities—one of today’s most critical risks in generative AI.
https://cranium.ai/cranium-launches-arena-the-industrys-first-ai-red-teaming-platform-that-extends-to-the-ai-supply-chain/ (read 2026-10-01)
Limit: From Arena red teaming, which tests for prompt injection rather than blocking it at runtime.AML.T0061—Detects instructions that tell AI agents to replicate themselves
https://docs.cranium.ai/en/articles/19622-adversarial-inputs-detector (read 2026-10-01)
Limit: A static scan of markdown command and rules files in named directories (.cursor/commands, .windsurf/workflows, .github instructions, agents.md, claude.md, gemini.md), not runtime detection.AML.T0081—Cranium's Adversarial Inputs Detector is a security tool that scans AI agent configuration files for potential malicious content, data exfiltration endpoints, self-propagation patterns, and hidden Unicode characters.
https://docs.cranium.ai/en/articles/19622-adversarial-inputs-detector (read 2026-10-01)
Limit: Scans the content of configuration files; it does not watch for or block writes to them.AML.T0054—Jailbreaking: Attempts to bypass safety guardrails through indirect manipulation, hypothetical scenarios, or roleplay.
https://docs.cranium.ai/en/articles/23108-profile-analysis-overview (read 2026-10-01)AML.T0068—Detects hidden characters that can conceal malicious instructions
https://docs.cranium.ai/en/articles/19622-adversarial-inputs-detector (read 2026-10-01)
Limit: Static scan of the same agent configuration files for zero-width, bidi, variation-selector and tag characters.AML.T0007—Cranium CodeSensor™ scans source code for models, datasets and AI packages
https://cranium.ai/platform/discover/ (read 2026-10-01)
Limit: Inventory from repository scanning, not detection of an adversary enumerating artefacts.AML.T0084—The table displays each agent's name, model, instructions, tools, handoffs, file paths, guardrails, and MCP servers.
https://docs.cranium.ai/en/articles/20411-agentsensor-overview (read 2026-10-01)
Limit: Repository scan of six agent frameworks (Strands, CrewAI, smolagents, AutoGen-AgentChat, LangGraph, OpenAI Agents); inventory only.AML.T0056—Prompt Leaking: Attempts to extract the system's internal instructions, prompts, or configuration details.
https://docs.cranium.ai/en/articles/23108-profile-analysis-overview (read 2026-10-01)AML.T0057—Prompt-injection, jailbreak and data-leakage simulation
https://cranium.ai/platform/secure/ (read 2026-10-01)
Limit: From Arena red teaming, which simulates data leakage rather than preventing it at runtime.AML.T0048—Illegality: References to illegal activities or instructions for unlawful behavior across categories such as cybercrime, fraud, drugs, violence, and terrorism.
https://docs.cranium.ai/en/articles/23108-profile-analysis-overview (read 2026-10-01)
CyCraft 8 of 76
CyCraft sells XecGuard, a cloud guardrail API that classifies prompts and responses for teams building chatbots and agents. Read 2026-10-01: cycraft.com XecGuard and XecART pages, two CyCraft press releases, the public XecGuard docs at community.cycraft.ai, and the xecclaw-plugin README on CyCraft's GitHub. XecGuard is a cloud guardrail API for prompts and responses (an LLM firewall built from fine-tuned small models), not an endpoint product; the only agent-side integration published is an OpenClaw plugin. XecART red-teaming claims (prompt injection, indirect injection, prompt disclosure, sensitive data leak) duplicate runtime cells and earn nothing extra. Not credited: Content Bias Protection (stereotypes, not AML.T0130 response biasing) and Context Grounding Validation (hallucination against RAG context, not RAG poisoning). CyCraft states limits plainly in its FAQ: 'XecGuard does not replace an organization's overall security governance mechanisms', it 'does not automatically rewrite user input', on-premise deployment 'is not part of our standard offering' (the 2025 launch release described an on-premises embedded firewall), and it is 'not recommended for scanning large documents or full-length files'. The PII Policy 'is not designed as a malicious activity detection alert'.
AML.T0051—It effectively blocks malicious inputs such as Prompt Injection, Prompt Extraction, and Harmful Content
https://www.cycraft.com/en/xecguard (read 2026-10-01)AML.T0053—It intercepts tool calls at runtime, scans for prompt injection, harmful content, PII leakage, and custom policy violations, and can block unsafe actions before execution.
https://github.com/cycraft-corp/xecclaw-plugin (read 2026-10-01)
Limit: An OpenClaw plugin only, which sends tool calls to the XecGuard cloud Scan API; no other agent integration is published.AML.T0110—Detects whether AI Agent Skills and related file content contain malicious or harmful content targeting the system
https://community.cycraft.ai/xecguard/doc/docs/intro/introduction (read 2026-10-01)
Limit: Content scan of skill text submitted to the API; CyCraft's FAQ says XecGuard is not recommended for scanning large documents or full-length files.AML.T0054—XecGuard provides robust protection against prompt injection, prompt extraction, and jailbreak attacks, ensuring enterprise-grade resilience for AI models.
https://www.cycraft.com/en/news/xecguard-launch-en-20250702 (read 2026-10-01)AML.T0068—capable of accurately uncovering underlying malicious intent—even when attackers use obfuscated encoding, role-play, or emotional persuasion tactics
https://www.cycraft.com/en/xecguard (read 2026-10-01)AML.T0056—Effectively block attackers attempting to override the model, expose system instructions, or bypass security mechanisms through obfuscation and encoding techniques.
https://www.cycraft.com/en/xecguard (read 2026-10-01)AML.T0057—Protect privacy and prevent data leakage of enterprise AI, supporting Taiwan personal data, addresses, and plate numbers, ensuring AI does not expose personal or sensitive information.
https://www.cycraft.com/en/xecguard (read 2026-10-01)
Limit: CyCraft's FAQ says the PII Policy detects personal-information attributes broadly at a low risk level and 'is not designed as a malicious activity detection alert'.AML.T0048—Use semantic analysis to detect and prevent AI outputs that violate public morals or contain violence, hatred, or danger.
https://www.cycraft.com/en/xecguard (read 2026-10-01)
Levo.ai 11 of 76
Levo.ai secures the AI applications, agents and MCP servers an enterprise runs in production, from eBPF sensors and inline enforcement on the server side. Read 2026-10-01 from levo.ai product pages only (the FAQ blocks on each product page carry most of the claims). Levo is an eBPF runtime-visibility platform for in-house AI apps, agents, MCP servers and APIs; most claims are about server-side traffic it observes or sits inline on, not about employee devices. Its AI Threat Detection FAQ states that detection 'does not sit inline or block by default'; blocking is a separate Inline Guardrails / AI Firewall product. Several cells come from the red-teaming and MCP security testing pages and describe pre-deployment testing, not runtime prevention, and are bounded accordingly. Explanations of attacks on the MCP and RAG pages (hidden instructions in tool descriptions, supply-chain risk of third-party MCP servers, memory leaking across sessions) were not credited because the pages explain them rather than claim a control. MCP Discovery (endpoint inventory via MDM) was read as governance/inventory, not adversary-technique coverage, and was not credited. docs.levo.ai was not read in depth.
AML.T0051—it can block malicious instructions from external documents (indirect prompt injection)
https://www.levo.ai/ai-security/ai-firewall (read 2026-10-01)
Limit: AI Firewall (inline) product for in-house AI applications; FAQ answer.AML.T0053—Levo enforces clear boundaries on what agents can do, which tools they can call, and what parameters they can pass, inline and in real time.
https://www.levo.ai/ai-security/ai-firewall (read 2026-10-01)AML.T0070—continuously tests for hallucinations or poisoning in outputs
https://www.levo.ai/ai-security/rag-security (read 2026-10-01)
Limit: Testing of RAG outputs for signs of poisoning, not inspection of what is ingested into the index.AML.T0110—Levo explicitly tests tool poisoning by simulating compromised tool outputs and edge case payloads.
https://www.levo.ai/ai-security/mcp-security-testing (read 2026-10-01)
Limit: Pre-deployment security testing of MCP servers, not runtime prevention; covers poisoned tool output (runtime response), not poisoned tool definitions.AML.T0054—Levo filters user inputs and model outputs in real time to block jailbreaks, prompt misuse, hallucinations, and toxic content.
https://www.levo.ai/ai-security/llm-security (read 2026-10-01)AML.T0068—detecting malicious patterns like obfuscated instructions or indirect jailbreak attempts
https://www.levo.ai/ai-security/llm-security (read 2026-10-01)AML.T0024—AI-specific protections ship pre-configured: from model extraction attempts to excessive vector queries.
https://www.levo.ai/ai-security/ai-attack-protection (read 2026-10-01)
Limit: Names model extraction only (AML.T0024.002); no claim for membership inference or model inversion.AML.T0056—Levo prevents sensitive system prompts and internal instructions from leaving your environment, even when users try to coax them out indirectly.
https://www.levo.ai/ai-security/ai-firewall (read 2026-10-01)AML.T0057—Levo applies AI-aware data protection inline to prevent sensitive data from being exposed through prompts or responses.
https://www.levo.ai/ai-security/ai-firewall (read 2026-10-01)AML.T0086—Levo blocks agents from overstepping access boundaries, leaking data, or chaining into risky actions.
https://www.levo.ai/ai-security/ai-agent-security-platform (read 2026-10-01)
Limit: General agent-enforcement claim; does not name a specific tool-invocation exfiltration mechanism.AML.T0034—Guardrails detect excessive token use, recursive chains, and long running sessions.
https://www.levo.ai/ai-security/ai-attack-protection (read 2026-10-01)
PointGuard AI 19 of 76
PointGuard AI sells AI security posture management, red teaming, an MCP gateway, agent identity and an AI-EDR endpoint client. Read 1 October 2026: about 380 pages of pointguardai.com (platform pages, 31 use cases, 150 blog posts, 72 news items, case studies, FAQs). The 223 glossary entries and the 137-entry AI Security Incident Tracker were not scored, nor were third-party report excerpts or a republished trade-press article on the news page. PointGuard AI was formerly AppSOC; older posts use that name. The use-case page titled 'Discover Coding Agents Across Developer Environments' carries body copy about open-source model governance, so nothing was scored from it. Inventory cells are bounded. The 36,527-server MCP study grades servers A to F using code scanning plus GitHub adoption signals; it is a rating, not a runtime control, and is scored as one supply-chain cell. PointGuard documents no limits of its own on the pages read. Not credited: a sentence listing 'unsafe content' among what its guardrails inspect, which appears only in a post about third-party recognition, and a sentence on prompt-injection indicators in metadata and surrounding content, which is indirect prompt injection, already credited, rather than obfuscation.
AML.T0018—Use automated scanning and red teaming to evaluate models for vulnerabilities, embedded malware, prompt injection exposure, toxicity, bias, unsafe behavior, and other weaknesses.
https://www.pointguardai.com/use-cases/identify-assess-risk-of-open-source-models (read 2026-10-01)AML.T0118—Authenticate participating agents and encrypt agent-to-agent interactions to protect exchanged information.
https://www.pointguardai.com/use-cases/secure-agent-to-agent-communication (read 2026-10-01)AML.T0010—By evaluating thousands of MCP servers and assigning transparent ratings, organizations can quickly assess trust, reduce AI supply chain risk, and adopt integrations with confidence.
https://www.pointguardai.com/mcp-security-gateway (read 2026-10-01)
Limit: A rating of the server, weighted 50% security, 30% operational and 20% adoption maturity per PointGuard's own methodology post, not a runtime block.AML.T0132—PointGuard AI scans AI components to detect misconfigurations, access control issues, and a broad range of security flaws.
https://www.pointguardai.com/ai-security-posture-management (read 2026-10-01)
Limit: A posture finding on MLOps platforms, not runtime enforcement.AML.T0011—Scans responses for malware or malicious code
https://www.pointguardai.com/ai-intelligent-guardrails (read 2026-10-01)AML.T0051—The solution also inspects prompt payloads to block prompt injection or jailbreak attacks
https://www.pointguardai.com/ai-intelligent-guardrails (read 2026-10-01)AML.T0053—Intercept and evaluate every agent action before it reaches enterprise systems.
https://www.pointguardai.com/guardian-agent (read 2026-10-01)AML.T0103—Continuously discover coding agents, AI browsers, desktop AI applications, local models, MCP servers, and agent frameworks operating across managed endpoints.
https://www.pointguardai.com/agentic-endpoint-security (read 2026-10-01)
Limit: Inventory on managed endpoints rather than detection of an adversary-deployed agent.AML.T0099—when an AI agent retrieves a file from GitHub or another MCP-connected tool, PointGuard inspects the content before it is sent to the model.
https://www.pointguardai.com/news/pointguard-ai-launches-advanced-guardrails-to-prevent-indirect-prompt-injection-attacks (read 2026-10-01)AML.T0110—Our MCP Gateway sits between your agents and their tools as a single policy enforcement point: tool- and operation-level authorization, read/write separation, and content inspection on every call — so a low-scoring or poisoned server cannot silently redirect an agent.
https://www.pointguardai.com/blog/we-tested-36-500-public-mcp-servers-two-thirds-arent-safe-for-enterprise-use (read 2026-10-01)AML.T0054—Detect prompt injection and jailbreak attempts
https://www.pointguardai.com/mcp-security-gateway (read 2026-10-01)AML.T0007—PointGuard AI provides AI Discovery and AI-BOM capabilities that continuously inventory models, agents, MCP servers, datasets, and third-party AI dependencies across enterprise environments.
https://www.pointguardai.com/blog/ciso-checklist-ai-agent-security-controls (read 2026-10-01)
Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.AML.T0057—By scanning both prompts and responses in real time, the platform prevents sensitive information from leaving your organization
https://www.pointguardai.com/ai-data-protection (read 2026-10-01)AML.T0086—DLP policies can be enforced directly at the MCP Gateway to prevent data exfiltration across agent interactions and connected systems.
https://www.pointguardai.com/mcp-security-gateway (read 2026-10-01)AML.T0034—Detect goal drift, repeated no-progress tool calls, unbounded planning loops, privilege escalation, abnormal tool usage, and out-of-scope access in real time.
https://www.pointguardai.com/guardian-agent (read 2026-10-01)
Limit: Framed as runaway-loop and drift detection, not as an adversary driving up cost.AML.T0101—Enforces policies at runtime—e.g., preventing DB schema drops or production mutations.
https://www.pointguardai.com/blog/delete-happens-why-ai-agents-need-guardrails (read 2026-10-01)AML.T0112—If a coding assistant suddenly tries to open a network socket or spawn a shell, we identify and block it as abnormal.
https://www.pointguardai.com/blog/hidden-risks-for-ai-agents-shadowmq-and-mcp (read 2026-10-01)AML.T0083—Move autonomous agents from static API keys and long-lived secrets to identity-based, scoped, time-bound credentials.
https://www.pointguardai.com/use-cases/eliminate-static-agent-credentials (read 2026-10-01)
Limit: Removes standing credentials from agent configuration rather than detecting their theft.AML.T0098—Inspect prompts, instructions, responses, and tool traffic for prompt injection, malicious instructions, credentials, and sensitive information.
https://www.pointguardai.com/use-cases/prevent-ai-threats-at-the-endpoint-ai-edr (read 2026-10-01)
Limit: Managed macOS, Windows and Linux endpoints running PointGuard's endpoint client.
Singulr AI 4 of 76
Singulr AI sells an enterprise AI governance platform (discovery, policy, approvals and audit across SaaS, cloud and browser) with runtime controls it has extended to endpoint coding agents. Read 2026-10-01 from singulr.ai product, solution, FAQ and blog pages. Its press release on extending Agent Pulse to endpoint agents (Claude Code, Cowork, Cursor, ChatGPT Desktop, MCPs) is hosted on BusinessWire, which returned 403/Access Denied to both fetch and browser; only the one-line homepage banner was read. docs.singulr.ai returned an empty page. Most of Singulr's material is governance (shadow-AI discovery, approval workflows, DLP on employee prompts), which this method does not count as adversary-technique coverage. Its runtime-security page lists 'Unauthorized data exfiltration detection.' without saying which path (user, model output or agent tool), so it was not assigned a technique. Its red-teaming FAQ names prompt injection, data poisoning and compliance violations in a single sentence describing testing; not credited beyond the runtime cells. The supply-chain cell comes from a blog post that maps Agent Pulse onto the LiteLLM compromise, mostly in counterfactual 'would have' language; only the present-tense drift-detection sentence is credited.
AML.T0010—detects configuration drift the moment it occurs, a modified proxy_server.py or a new .pth file in site-packages triggers a policy violation alert against your approved baseline.
https://www.singulr.ai/blog/when-your-security-scanner-becomes-the-weapon-litellm-supply-chain-attack-breakdown (read 2026-10-01)
Limit: Drift detection against an approved baseline, described in a post that maps the product onto the LiteLLM compromise after the fact; the rest of that mapping is counterfactual ('would have').AML.T0051—Prompt injection attack detection.
https://www.singulr.ai/products/runtime-security (read 2026-10-01)AML.T0053—Agent permission boundaries are enforced at execution.
https://www.singulr.ai/products/runtime-control (read 2026-10-01)AML.T0054—Adversarial and jailbreak attack detection.
https://www.singulr.ai/products/runtime-security (read 2026-10-01)
Trustwise 6 of 76
Trustwise sells a runtime policy and compliance layer for agents that enterprises build, integrated through frameworks and SDKs. Read 2026-10-01 from trustwise.ai (product, pricing, solutions, press and blog pages). Most security claims are about Harmony AI's 'Shields' (Prompt, MCP, Compliance, Brand, Cost, Carbon), introduced in a June 2025 launch post and press release that described Harmony AI as being 'in private preview to select Trustwise customers and OEM partners'. The current site reframes the product as the 'AI Control Plane' (Assess / Control / Optimize) and says less about specific detections. The 'Where AI Runs' page lists coding agents (Claude Code, GitHub Copilot, Cursor, Codex, Windsurf, Amazon Q Developer), stating Trustwise governs them 'without replacing code review, SAST, or SDLC controls', but does not say how it attaches to them. The site states framework mapping to MITRE ATLAS among 1,100+ controls, but publishes no per-technique list, so that earns nothing. The '20,000+ Red-Team Prompts' dataset (injection, jailbreak, misuse, drift) was not credited separately from the runtime cells. Several blog posts explain prompt injection; only the product sentences were credited.
AML.T0051—Prevents injection attacks, hallucinations, and off-policy outputs through dynamic prompt-level safeguards
https://trustwise.ai/trustwise-introduces-the-first-trust-layer-for-agentic-ai/ (read 2026-10-01)
Limit: June 2025 launch press release; the product was then in private preview.AML.T0053—Prevents unauthorized tool use and execution drift.
https://trustwise.ai/introducing-agentic-ai-shields-the-trust-layer-for-modern-enterprise-ai/ (read 2026-10-01)AML.T0110—Prevents an agent from acting on a hidden system prompt injected through a user message or tool description.
https://trustwise.ai/introducing-agentic-ai-shields-the-trust-layer-for-modern-enterprise-ai/ (read 2026-10-01)
Limit: Given as an example of the Prompt Shield; covers instructions hidden in a tool description (definition), not compromised tool implementations or runtime responses.AML.T0054—Detects attempts to override system instructions, disable safety mechanisms, or inject unauthorized commands.
https://trustwise.ai/prompt-injection-the-silent-killer-of-trust-in-ai/ (read 2026-10-01)AML.T0057—Analyzes AI responses to detect and block the output of PII, intellectual property, or confidential information before it reaches the user.
https://trustwise.ai/prompt-injection-the-silent-killer-of-trust-in-ai/ (read 2026-10-01)AML.T0034—Detects and halts recursive logic loops that drive up token costs while routing low-priority queries to more efficient models.
https://trustwise.ai/introducing-agentic-ai-shields-the-trust-layer-for-modern-enterprise-ai/ (read 2026-10-01)
Limit: Framed as cost optimisation of runaway agent loops rather than defence against an adversary inflating cost.
Vijil 6 of 76
Vijil helps teams building agents test and harden them, and ships guardrails that run inside the agent's own code. Read 2026-10-01 from vijil.ai, docs.vijil.ai and the Apache-2.0 vijil-dome README on GitHub (github.com/vijilAI/vijil-dome). Vijil protects agents that the customer builds: Dome is a library and request-path guardrail inside the agent (LangGraph, Google ADK, Strands, MCP tool wrapping), and Diamond is a pre-deployment evaluation and red-team harness. Several cells are drawn from guard tables in the owner guide (threat name followed by its description); the quote is the row as it renders on the page. Dome's README also describes verifying tool identity against a signed manifest via SPIFFE; this was not credited because the prose describes an identity mechanism without stating which adversary technique it addresses. Diamond's security scenarios also include data-leakage, model-privacy, malware and exploit-generation probes; only the denial-of-service probes were credited, as a testing-only cell. No claims were found for RAG poisoning, MCP tool poisoning, memory poisoning or system-prompt extraction as runtime defences.
AML.T0051—Prompt injection Attempts to override system or developer instructions
https://docs.vijil.ai/owner-guide/protect-in-production/configuring-guardrails (read 2026-10-01)AML.T0053—Checks each tool call against the agent's permission policy before execution
https://github.com/vijilAI/vijil-dome (read 2026-10-01)
Limit: Library-level enforcement inside agents built with supported frameworks (or wrapped tools); not an interception point for third-party agents.AML.T0054—Jailbreaks Attempts to bypass safety or policy constraints
https://docs.vijil.ai/owner-guide/protect-in-production/configuring-guardrails (read 2026-10-01)AML.T0068—Encoded attacks Payloads hidden in Base64, Unicode tricks, or similar encodings
https://docs.vijil.ai/owner-guide/protect-in-production/configuring-guardrails (read 2026-10-01)AML.T0057—Enable Privacy Guards on outputs to reduce sensitive-data leakage.
https://docs.vijil.ai/owner-guide/protect-in-production/configuring-guardrails (read 2026-10-01)AML.T0029—Tests for denial of service resistance using uppercase mutation
https://docs.vijil.ai/concepts/trust-score/security (read 2026-10-01)
Limit: A Diamond evaluation probe (pre-deployment testing), not a runtime control.
So you can check any cell against the vendor’s page yourself — and tell us where we read it wrong. The 26 September correction started that way.
What we checked and did not credit
The candidates checked in the 26 September correction that did not become cells, and why. Each quote was confirmed on the live page first; every one of them is a real sentence from the product’s own material, so a different reviewer could reasonably file some of them differently.
Scroll sideways →
| Product | Technique | Why it was not credited |
|---|---|---|
| SentinelOne (Prompt Security) | T0071 | Same ingestion scan as its new RAG-poisoning (T0070) cell, and T0070 contains false RAG entries. |
| Lakera | T0071 | Same ingestion scan as its existing RAG-poisoning (T0070) cell, and T0070 contains false RAG entries. source |
| Lakera | T0067 | The sentence is already its User Execution (T0011) cell; one link filter earns one cell. source |
| Lakera | T0069 | The sentence is already its system-prompt extraction (T0056) cell, which T0069's system-prompt sub-technique restates. source |
| Straiker | T0069 | Already its system-prompt extraction (T0056) cell; same restatement. source |
| Netskope | T0069 | Already its system-prompt extraction (T0056) cell; same restatement. |
| Netskope | T0067 | Malicious-URL filtering, the capability its existing User Execution (T0011) cell already credits. source |
| Netskope | T0059 | One control earns one cell; the sentence names training and data poisoning, so it is credited to T0020. source |
| Zenity | T0067 | Links are filed under T0011, which Zenity holds; the sentence's image-rendering detection is credited to T0077. source |
| Zenity | T0096 | The sentence is already its AI-agent C2 (T0108) cell and names one detection. source |
| Straiker | T0093 | The sentence is already its tool-data poisoning (T0099) cell; ATLAS says the two overlap. source |
| Certiv | T0071, T0092, T0094 | A copied OWASP category definition with no claim sentence, the basis on which Operant's OWASP badges were not counted. source |
| Backslash Security | T0093 | Tickets are named in an explanation of where injection comes from, not in what the product inspects. source |
| MoorAI (prose review) | T0071 | Same ingestion scan as its prose RAG-poisoning (T0070) credit; judged as Lakera's was. source |
Questions about this study
How were vendors credited for a MITRE ATLAS technique?
It is a documentation review. A vendor is credited for a technique only where its own published material describes doing the thing the technique describes, backed by a source URL and a verbatim quote. Explaining an attack is not covering it, governing usage of AI is not defending against an adversary, and third-party prose on a vendor's site does not count. The scope is the 76 top-level techniques MITRE's ATLAS 2026.09 release tags with the platform Agentic AI.
Which ATLAS agentic techniques do the most vendors document?
AML.T0053 AI Agent Tool Invocation (36 of 43 vendors), AML.T0051 LLM Prompt Injection (35), AML.T0057 LLM Data Leakage (33) and AML.T0086 Exfiltration via AI Agent Tool Invocation (30). Coverage is less concentrated than that list suggests: those four hold 134 of the 517 vendor credits, 26%, and it takes the eleven most-documented techniques to pass half. Of the 548 credits in the review, MoorAI's rule base included, 220 come with a limit the product states itself; tool invocation and deploying an agent carry the most, eighteen each.
Which ATLAS agentic techniques does no vendor document?
32 of the 76 are documented by none of the 43 vendors reviewed; MoorAI's rule base holds five of those, leaving 27 that no product in the review documents. Three of the five were added by MoorAI agent v0.96.0, released on 26 September, after the study. By ATLAS's own tactic definitions, 11 of the 27 are adversary preparation (Reconnaissance, Resource Development, AI Attack Adaptation) and 6 sit in Discovery or AI Model Access. The other 10 are defence-side: 4 in Defense Evasion, 4 in Impact and 2 in Command and Control. Products outside this sample publish material on some of them. A further 9 techniques are documented by exactly one vendor.
Does an empty cell mean a product lacks the capability?
No. An empty cell means nothing was found published, not that a product lacks the capability. Nothing was installed or run; every credit is a claim, including MoorAI's. A low count usually reflects a category, such as a data-loss-prevention platform, rather than a weakness.
How does MoorAI score under the same method?
Scored from published prose only, the way vendors are scored, MoorAI comes out at 31 techniques, and 26 after discarding every credit traceable to one README bullet that names ATLAS ids. On the 20 September read date its rule base gave 27, so the prose method was the more generous of the two. MoorAI agent v0.96.0, released on 26 September and prompted by this study's gaps, added rules for four more techniques; the rule base now gives 31, and the prose review has not been re-run against that release. The current release, agent v1.1.0 of 1 October 2026, carries the same ATLAS mapping. The asymmetry is vocabulary: MoorAI's documentation is written in ATLAS's language, which a prose review rewards.
Changes to this study
The study was first published on 21 September 2026. Every correction, update and expansion since is recorded here with the figures of its own day; the rest of this page states the study as it stands now.
Corrected 26 September 2026
An independent audit of this study, first published on 21 September, found claims the data did not support and vendor evidence the review had missed. We checked every point against the sources and changed the study where it was wrong.
- Four credits added from vendors’ own material, each quote checked on the live page on 26 September. Certiv documents prompt injection arriving in emails and documents (AML.T0093). SentinelOne’s Prompt Security line documents scanning content before it is embedded in a RAG index (AML.T0070). Zenity documents detecting risky image rendering in model output (AML.T0077). Netskope documents keeping poisoned data out of training data stores, in a hedged press-release sentence recorded as bounded (AML.T0020). Credits went from 249 to 253, bounded credits from 75 to 76, and techniques no product here documents from 32 to 31.
- 15 further vendor candidates were checked and not credited. Most were sentences already credited to a neighbouring technique, and one sentence earns one cell under the rule applied to every row; two of those sentences fit a different technique better and are credited there (the Netskope and Zenity cells above). The rest were a copied framework definition or an explanation of an attack. Each is listed under What we checked and did not credit, with the reason.
- Preparation was reclassified. We had counted Discovery and AI Model Access as attacker preparation. ATLAS does not: it describes Discovery as post-compromise. Preparation now means Reconnaissance, Resource Development and AI Attack Adaptation only, 11 of the 31 rather than 17. Six techniques in Discovery and AI Model Access are listed apart, and defence-side techniques number 14 rather than 15, because Certiv now documents AML.T0093.
- Two claims are withdrawn. “Four techniques carry most of the industry’s published coverage”: they carry 26% of vendor credits, and it takes eleven to pass half. “The qualification clusters on the crowded techniques”: true for tool invocation and tool-invocation exfiltration, not for prompt injection or data leakage.
- Three claims are narrowed. Defense Evasion has the most undocumented defence-side techniques by count, six of eleven, but Command and Control is emptier by share, and five Defense Evasion techniques do have coverage. It was wrong that no defensive product claims preparation-stage techniques: vendors document nine techniques in those five tactics. And “nobody” means nobody in this sample. MoorAI’s own published prose describes two of the 31, which the post had denied, and products outside the sample publish material on several.
Updated 26 September 2026: MoorAI agent v0.96.0
MoorAI agent v0.96.0, released on 26 September, adds five rules to the rule base. Four of them carry techniques this study had listed as documented by no product: AML.T0061 LLM Prompt Self-Replication; AML.T0092 Manipulate User LLM Chat History, bounded to local agent transcript files; AML.T0067 LLM Trusted Output Components Manipulation, bounded to links; and AML.T0035 AI Artifact Collection, bounded to model files and caches moved in one command. The fifth maps model-loading calls to AML.T0011.000, a sub-technique of User Execution, which MoorAI’s rule base already held, so it changes no cell.
These rules were written after the study, prompted by the gaps it found. None of them existed on the 20 September read date. Only MoorAI’s row changed: its rule base now gives 31 of 76 rather than 27. No vendor cell changed. Techniques no product here documents fall from 31 to 27, and defence-side ones from 14 to 10; credits go from 253 to 257. The prose review of MoorAI has not been re-run against the new release.
This update also corrects MoorAI’s bounded cells, which were understated on the read date too. The rule base records a limit on every credit that covers only part of a technique, but the chart drew only a hand-picked list of them as bounded. A MoorAI cell is now drawn bounded whenever every rule crediting it is partial: 13 of 27 on the read date, where the post showed 4, and 16 of 31 now, where the hand-picked list would have shown 7. Bounded credits across the review go from 76 to 88; on the read date the figure should have been 85. Vendor cells are unaffected. The figures in the correction note above are as they stood before this update.
Expanded 27 September 2026: four vendors added
Four vendors were added to the study on 27 September: Lasso Security, Permiso, Pillar Security and WitnessAI. They appear on an analyst’s market map of agentic runtime enforcement, and three of them document coverage of AI coding agents; Permiso covers AI agents through identity and cloud logs. They were read on 27 September by the same method as the original 19, and every quote was checked as an exact match on the vendor’s page that day. All four keep their product documentation behind a login or a password, so their cells come from marketing sites, blogs, first-party PDFs and, for Lasso, open-source repositories. Each vendor’s note in the sources above says what was read and what was not credited.
What moved. The study now covers 23 vendors. Pillar Security documents 26 techniques, more than any vendor in the original read, where Operant AI and Zenity led with 23; Lasso Security documents 23, WitnessAI 14 and Permiso 9. Vendor credits go from 226 to 298, and all credits from 257 to 329, of which 111 are bounded rather than 88. The median vendor documents 14 rather than 12, and 9 of the 23 document fewer than ten, against 8 of 19. The four most-documented techniques hold 24% of vendor credits rather than 26%, and it still takes eleven to pass half. Techniques documented by exactly one vendor fall from twelve to ten: Pillar Security also documents AML.T0093, and WitnessAI AML.T0129.
What did not. None of the four documents a technique that no vendor documented before: the 43 techniques with any vendor coverage are the same 43. So the 27 techniques no product here documents, their split into 10 defence-side, 6 in Discovery or AI Model Access and 11 preparation, and the 33 no vendor documents are all unchanged, and so is MoorAI’s row. The correction and update notes above keep their figures as published, for the 19 vendors of the original read.
Expanded 1 October 2026: two vendors added
Two vendors were added to the study on 1 October: Above Security and Rig Security. Above sells an insider-risk platform whose AI agents investigate cases from identity, SaaS, endpoint and AI-tool connectors, and its research group co-wrote the Synthetic Insider Threat Matrix. Rig sells identity security for people, machine identities and AI agents, with an endpoint sensor that enforces policy before an agent’s action runs. They were read on 1 October by the same method, and every quote was checked as an exact match on the vendor’s page that day. Rig publishes no product documentation and Above’s customer portal is behind a login, so their cells come from product pages, blogs and first-party PDFs. Each vendor’s note in the sources above says what was read and what was not credited. Our mapping of MoorAI against that matrix is a separate post.
What moved. The study now covers 25 vendors. Above Security documents 2 techniques and Rig Security 2, every one of them with a limit: Above’s are investigation after the fact, and Rig’s are keyed to identity and resource rather than to content. Vendor credits go from 298 to 302, and all credits from 329 to 333, of which 115 are bounded rather than 111. The median vendor documents 12 rather than 14, and 11 of the 25 document fewer than ten, against 9 of 23. The four most-documented techniques still hold 24% of vendor credits, and it still takes eleven to pass half.
What did not. Neither documents a technique that no vendor documented before, and neither changes which techniques have exactly one vendor. The 27 techniques no product here documents, the 33 no vendor documents and MoorAI’s row are unchanged. The notes above keep their figures as published.
Expanded again 1 October 2026: eighteen vendors added
Eighteen vendors were added to the study later on 1 October: Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Singulr AI, Trustwise, Vijil and Virtue AI. They sell AI runtime guardrails and firewalls, AI and MCP gateways, agent discovery and posture, model scanning and red teaming, and many of them describe reaching AI coding agents through a hook in the agent, an endpoint client or a gateway in front of the model. The evidence is each vendor’s own first-party material, read on 1 October: product pages, public documentation, blogs, press releases and GitHub repositories, and for Virtue AI, which Fortinet has acquired, Fortinet’s own release. Every quote was checked as an exact match on the vendor’s live page that day. Analyst content and third-party write-ups were not used. Four proposed cells were not credited under the rules below: a typosquatted package is not a hallucinated entity, one model scanner earns one cell, indirect injection is not obfuscation, and a sentence found only in a post about third-party recognition was set aside. Each vendor’s note in the sources above says what was read and what was not credited.
What moved. The study now covers 43 vendors. The eighteen document 215 techniques between them, 105 of them with a limit; Akto documents the most of the eighteen, 21, and Pillar Security still leads the study with 26. Vendor credits go from 302 to 517, and all credits from 333 to 548, of which 220 are bounded rather than 115: two in five rather than about a third. The median vendor documents 11 rather than 12, and 18 of the 43 document fewer than ten, against 11 of 25. The four most-documented techniques hold 26% of vendor credits rather than 24%, and it still takes eleven to pass half; AI Agent Tool Invocation, AML.T0053, now leads, documented by 36. Techniques documented by exactly one vendor fall from ten to nine: five of the eighteen also document AML.T0018 and one AML.T0024, and Cranium documents AML.T0061, which no vendor had documented before.
What did not. AML.T0061 already had a MoorAI rule, so the 27 techniques no product here documents, their split into 10 defence-side, 6 in Discovery or AI Model Access and 11 preparation, and MoorAI’s row are unchanged. Counting vendors alone, techniques no vendor documents fall from 33 to 32. The notes above keep their figures as published.