AI Security Platform | Knostic
SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain
24 August 2026
CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
4 August 2026
Introducing AgentMesh Access Tiers: Building Together, Growing Together
27 July 2026
Lessons Learned from the Hugging Face Security Team
24 July 2026
Security Across the Agentic Lifecycle
Knostic discovers and secures AI agents and coding assistants, as well as associated supply chain risks, including MCP servers, skills, IDE extensions, and rules. We detect shadow AI, block data exfiltration, and stop destructive commands like rm -rf.
Get Started for Free
AgentMesh: AI Supply Chain Threat Intel
OpenAnt: Open Source Vulnerability Discovery
OpenClaw Detect: OpenClaw Discovery
Latest News and Blog Releases
SaassyCode Repackaged: Four New VS Code Extensions and a New ...
Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package was republished almost ...
CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
CodeRelay is the name we gave to a coordinated campaign involving 13 malicious VSIX packages across 12 VS Code extensions. Most look like compiler, code-runner, or “timeline” ...
Introducing AgentMesh Access Tiers: Building Together, ...
We've been blown away by the response to Knostic AgentMesh since we opened it up to the community. The validation of watching security researchers, developers, and enterprise ...
The AI Empowered-IDE Represents an Exposed, Unaddressed Control Point
Security leaders lack visibility and control within the AI-empowered IDE, while AI coding agents expand the attack surface to IDEs and developer workstations through plain-language inputs such as MCP servers, extensions, prompts, and rules.
Agents act fast and can make destructive mistakes, such as running rm-rf on your code or entire machine.
Organizations lack visibility and policy enforcement across extensions, MCP servers, rules, skills, and hooks.
AI coding agents have led to a proliferation of insecure, AI-generated code throughout the organization.
Knostic Enables Secure Use of Agents in the Enterprise Without Disrupting Workflows
Coding Agents & MCP
Secure AI coding tools and autonomous agents without disrupting workflows.
- Agent discovery (Cursor, Claude, etc.)
- Detection & Response
- Inventory / Supply chain
- Security Posture Management
- Reputation service
Citizen Coders
Discover, monitor, and secure applications built by citizen coders.
- Discovery (repl.it, Lovable, bots)
- Monitoring for new applications
- Policy enforcement
- AppSec controls
OpenClaw
Secure OpenClaw from secret leaks, PII exposure, and destructive commands.
- Blocks destructive commands
- Redacts secrets and API keys
- Prevents PII exposure
- Logs and flags inbound secrets
- Gates exec and file-read operations
AI-Generated Code / AI-SDLC
Discover, detect, and manage the security posture of your AI coding agents.
- AI threat modeling
- Vibe-coded vs. manual measurements
- AI-driven vulnerability discovery & remediation
- Dynamic rules & secure coding
OpenAnt / Agentic Vulnerability Scanning
LLM-powered vulnerability discovery for CI/CD pipelines.
- Two-stage verification: Stage 1 detects, Stage 2 attacks - what survives is real
- Semantic code understanding (not pattern matching)
- Function analysis with dependencies, callers, and call context
- Minimizes false positives and false negatives
- Available in open source and as a managed service