Skip to content
MoorAI
// security for ai · the map

Security for AI: securing the agents themselves

“AI security” usually means AI doing security work: triage, detection and response in the SOC. Security for AI is the other direction: securing the AI agents your people run and the agents you ship. MoorAI secures AI agents. It is not AI for the SOC.

Securing agents splits into five categories. Below is each one, what MoorAI does in it, and where it stops.

01

Runtime

Strong

Sandboxing, action interception, tool and MCP security, runtime policy, secret and data protection.

Covered

  • A check before each tool call in coding agents, validated end to end in Claude Code
  • A model proxy, an MCP gateway and a stdio MCP proxy
  • An egress proxy that enforces egress rules on real connections
  • On-device DLP: secrets and PII masked or blocked
  • Placeholder credentials (opt-in): the agent holds a stand-in, not the real key
  • Sandbox network policy generated from the same rules for Windows MXC, macOS Seatbelt and an open-source agent sandbox

Where it stops

  • No sandbox of its own: it is governance, and its hook fails open if it crashes or times out
02

Accountability

Strong

Audit trail, attribution, behaviour monitoring, incident response.

Covered

  • Hash-chained evidence logs: a deleted, reordered or edited record breaks the chain
  • A content-free session ledger and exposure ledger on the device
  • Events attributed to a keyed actor hash
  • A keyed session hash on alerts from a known agent session, so they group together
  • Learned-drift and session-risk detection, and a runaway-loop breaker
  • Session kill: end the running agent, not just the one call

Where it stops

  • No incident-response tool integrations; events stream to a SIEM over OpenTelemetry
03

Governance

Strong

Orchestration governance, policy as code, approvals and escalation, compliance.

Covered

  • A signed policy, fleet-wide or per device
  • Justify and sign-off: hold a risky act for a signed justification
  • The entitlement envelope: an agent's authorized tools, paths and MCP servers, applied to its sub-agents too
  • Every rule mapped to the OWASP LLM Top 10, MITRE ATLAS, the OWASP Top 10 for Agentic Applications and the OWASP MCP Top 10 (beta)

Where it stops

  • Blocking, sign-off and session kill apply on enrolled devices; an unenrolled device coaches only
04

Access

Partial

Authentication, authorization, credential management, agent-to-agent trust.

Covered

  • Tool authorization: MCP allow-lists, server approval and tool-argument checks
  • Egress rules per binary, host, port, method and path
  • Placeholder credentials, swapped for the real secret only on its own route

Where it stops

  • No agent authentication
  • No trust between agents beyond recording delegation and scanning the delegated prompt
05

Identity

Partial

Agent and sub-agent identity, lifecycle, provenance, delegation.

Covered

  • A keyed actor hash per user and machine
  • Workload identity on server-side alerts: container, pod, namespace and node
  • Sub-agent spawns recorded

Where it stops

  • No per-agent identity registry or lifecycle
  • No delegation chain an agent can present

The frameworks people point at

Each one links to its publisher. “Mapped” means every MoorAI rule is crosswalked to it on this site.

Framework From MoorAI
OWASP Top 10 for Agentic Applications 2026 OWASP GenAI Security Project, 9 December 2025 Mapped (ASI01–ASI10)
Agentic Trust Framework Cloud Security Alliance, February 2026 Not mapped
AI Agent Standards Initiative NIST Center for AI Standards and Innovation, February 2026 Not mapped
OpenID Connect Agent Identity Claims Individual Internet-Draft (draft-sharif-openid-agent-identity) Not mapped
AI Identity Management System (agents as workloads) IETF WIMSE working group Internet-Draft (draft-ietf-wimse-aims) Not mapped
SAF-MCP OpenSSF special interest group (SIG-SAF-MCP), an LF Projects series Not mapped
Careful Adoption of Agentic AI Services CISA with Australia's ASD's ACSC and international partners, 1 May 2026 Not mapped

The OpenID Connect agent-identity profile is an individual Internet-Draft, not an OpenID Foundation specification, and both Internet-Drafts are works in progress. MoorAI's rules are also mapped to the OWASP LLM Top 10, MITRE ATLAS and the OWASP MCP Top 10 (beta): see the threat rule-base.