# knostic.ai > AI-optimized mirror of knostic.ai containing 50 pages totalling 53,233 words of clean markdown content, structured data, and semantic HTML. Original source: https://knostic.ai. Last updated: 2026-09-01T08:18:01.527Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [AI Security Platform | Knostic](/content/site-root.html): Adopt AI confidently. Knostic provides enterprise-grade governance, visibility, and real-time protection across users, data, and AI tools. (504 words) ## Articles & Blog Posts - [SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain](/content/blog/saassycode-repackaged-four-new-vs-code-extensions-and-a-new-delivery-chain.html): Knostic reveals four new VS Code extensions that exploit SaassyCode's malicious code, showcasing evolving delivery methods and potential security risks. (1,556 words) - [CodeRelay: 12 VS Code Extensions Disguised as Developer Tools](/content/blog/coderelay-12-vs-code-extensions-disguised-as-developer-tools.html): CodeRelay: a coordinated campaign of 13 malicious VSIX packages across 12 VS Code extensions disguised as developer tools. Analysis, IOCs, and defenses. (1,297 words) - [Why MCP Governance Isn’t Optional Anymore](/content/blog/mcp-governance/index.html): Learn how to govern MCP configurations with role-based policies, access controls, and audit mechanisms for secure, compliant AI agent environments. (2,469 words) - [AI Usage Control (AI-UC): How to Prevent AI Misuse](/content/blog/ai-usage-control/index.html): Learn what AI Usage Control (AI-UC) is, how it prevents misuse, ensures compliance, and how Knostic enforces safe, explainable AI adoption. (2,527 words) - [Persona-based Access Control Implementation in Just 6 Steps](/content/blog/persona-based-access-control-strategy/index.html): Follow a proven PBAC rollout strategy. From persona discovery to live monitoring, learn the best practices that Knostic can automate in real time. (1,955 words) - [SaassyCode Post-Disclosure Wave: Five New Extensions, 32,000+ Total Installs](/content/blog/saassycode-post-disclosure-wave-five-new-extensions-32000-total-installs.html): New findings reveal a surge in malicious VS Code extensions, with over 32,000 installs. One extension remains live, posing serious risks to developers. (1,541 words) - [How to Measure and Audit AI Data Governance](/content/blog/ai-governance-measurement-audit/index.html): Measure and audit AI data governance with clear KPIs, dashboards, and audit trails. Track leakage, compliance, and policy hits, powered by Knostic. (2,997 words) - [Primer: AI Security Posture Management (AI-SPM)](/content/blog/ai-security-posture-management-aispm/index.html): See how AI-SPM inventories models and data, detects risks, proves compliance, and how Knostic adds real-time controls to stop oversharing. (1,770 words) - [Attribute-Based Access Control (ABAC) Implementation Guide](/content/blog/abac-implementation-strategy/index.html): Implement attribute-based access control for AI assistants and agents with clear steps, PDP/PEPs, policies, RBAC migration, and audit-ready KPIs. (2,190 words) - [Solving the Very-Real Problem of AI Hallucination](/content/blog/ai-hallucinations/index.html): AI hallucinations in enterprise tools cause misinformation, compliance risks, and loss of trust. Learn the causes and how Knostic prevents them. (2,138 words) - [Enterprise GenAI Adoption Mandate: Lessons from America’s AI Action Plan](/content/blog/enterprise-ai-adoption/index.html): Use the White House AI Action Plan to fast‑track GenAI adoption, sandboxes, skills, risk controls, and see how Knostic keeps oversharing at zero. (2,036 words) - [AI Adoption in Government & the Department of Defense](/content/blog/gen-ai-adoption-government/index.html): See how the Action Plan urges AI adoption across government and DoD, and turn its directives into a practical rollout with metrics and testbeds. (852 words) - [AI Coding Agent Governance Policies That Work](/content/blog/ai-coding-agent-governance/index.html): Define governance policies for AI coding agents, including access control, oversight, approvals, and auditability, to ensure safe and accountable deployment. (1,786 words) - [How AI Assistants Leak Secrets in Your IDE](/content/blog/ai-coding-assistants-leaking-secrets/index.html): Your IDE can leak secrets through your AI assistants. Discover how Claude Code, Cursor, and Windsurf find and expose tokens, and how to stop it. (1,283 words) - [New Malicious VS Code Extension Backdoor: Remote Text Fetcher](/content/blog/new-malicious-vs-code-extension-backdoor-remote-text-fetcher.html): A VS Code extension disguised as a text utility executes attacker-controlled shell commands on every startup, caught by AgentMesh before reaching any users (646 words) - [Securing Multi-Agent AI Development Systems](/content/blog/multi-agent-security/index.html): Multi-agent AI systems introduce new orchestration risks, from inter-agent prompt injection to unsafe capability sharing. (2,515 words) - [AI Safety vs. AI Security: Explaining the Differences](/content/blog/ai-safety-vs-ai-security/index.html): Learn the real difference between AI safety and AI security, why words matter, who owns the risk, and how to govern AI systems without losing the basics. (1,423 words) - [How to Detect and Block Malicious IDE Extensions](/content/blog/detect-suspicious-ide-extensions/index.html): Learn how to detect suspicious IDE extensions with behavioral analysis, permission review, and monitoring to protect your AI coding environment. (2,099 words) - [The Mechanics Behind MoltBook: Prompts, Skills & Timers](/content/blog/the-mechanics-behind-moltbook-prompts-timers-and-insecure-agents.html): MoltBook's emergent agent behavior traces to prompts and timers. We break down the mechanics, and why the same risks apply to your coding agents. (825 words) - [Primer: AI Governance Roles and Responsibilities](/content/blog/ai-governance-roles-stakeholders/index.html): Define AI governance roles, decision rights, RACI, handoffs, and KPIs. See who owns what and how to operationalize with Knostic. (1,157 words) - [Enhance Purview, E3, and E5 Investments with Knostic](/content/enhance-purview-e3-e5/index.html): Enhance Microsoft Purview with Knostic. Automate labeling, detect oversharing, and remediate risks in real time. (419 words) - [How Model Context Protocol (MCP) Servers Communicate](/content/blog/model-context-protocol-communication/index.html): Explore request-response cycles, channel protocols, and security tokens that power low-latency communication between MCP servers and GenAI models. (552 words) - [Automating the MCP Servers Discovery with Claude Sonnet 4](/content/blog/automating-model-context-protocol-discovery/index.html): Learn how Claude Sonnet 4 automates the discovery of Model Context Protocol servers, revealing hidden endpoints and boosting GenAI security oversight. (712 words) - [Enterprise AI Tools Know Too Much: The CISO’s Dillema](/content/blog/enterprise-ai-tools-data-exposure/index.html): Enterprise AI tools know too much, hoarding sensitive data. Explore the CISO’s dilemma, and learn strategies to secure knowledge-hungry models. (591 words) - [How Mental Models are Transforming AI Chaos into Clarity](/content/blog/mental-models-transforming-ai/index.html): At BSides Las Vegas, Knostic’s Sounil Yu shows how mental models (OODA, Cynefin & more) turn AI and cybersecurity chaos into clarity for better decisions. (631 words) - [Data Minimization & Retention Hygiene | Knostic](/content/the-genai-knowledge-security-platform/data-minimization-retention-hygiene/index.html): Find stale files LLM can still surface, then archive or delete them. Knostic quickly cleans up digital debt in SharePoint, OneDrive, and Teams. (370 words) - [Knowledge Security Platform for CISOs | Knostic](/content/roles/ciso/index.html): Gain full visibility into AI risks. Knostic redacts secrets, tracks knowledge access, and feeds real-time alerts to your SOC—without killing productivity. (336 words) - [The GitHub Breach and VS Code Extensions: Threat Intelligence and Agentic Defense](/content/blog/github-teampcp-breach-developer-supply-chain/index.html): The GitHub TeamPCP incident wasn't a one-off. It's the predictable result of an unmonitored developer agent surface. Here's what CISOs should do next. (1,156 words) - [Partner webpage](/content/partner-webpage/index.html): Partner webpage (247 words) - [Security Control Feedback Loop | Knostic](/content/the-genai-knowledge-security-platform/security-control-feedback-loop/index.html): See where DLP, RBAC, or Purview miss “least-privilege.” Knostic spots inference leaks, shows proof, and feeds fixes straight back into your controls. (351 words) - [DeepSeek’s cutoff date is July 2024: We extracted DeepSeek’s system prompt](/content/blog/exposing-deepseek-system-prompts/index.html): Discover how the (749 words) - [Automated AI Data Labeling Solution](/content/automated-ai-data-labeling-solution/index.html): Accelerate AI securely. Our automated data labeling solution classifies sensitive content to enforce security and compliance. (396 words) - [6 Biggest Shadow AI Risks and How to Mitigate Them](/content/blog/shadow-ai-risks/index.html): Unapproved AI tools are leaking data, breaking compliance, and hiding vulnerabilities. Expose the biggest shadow AI risks and how to eliminate them safely. (902 words) - [Knowledge Security Platform for Red Teams & Pen Testers | Knostic](/content/roles/red-teams-pen-testers/index.html): Expose true AI attack paths. Knostic generates malicious prompts, traces knowledge leaks, and delivers board-ready impact reports for red teams. (287 words) - [No-Code Deployment | Knostic](/content/the-genai-knowledge-security-platform/no-code-deployment/index.html): Roll out Knostic in days, not months. Zero agents, zero code. Just connect to M365, Copilot, or Glean and start seeing AI-security insights fast. (337 words) - [Knowledge Graph Mapping | Knostic](/content/the-genai-knowledge-security-platform/knowledge-graph-mapping/index.html): Knostic draws a live, easy-to-read map of people, info, and access rights, so you can spot gaps, overlaps, and hidden experts in minutes. (256 words) - [AI as an Enzyme to Transform Critical Infrastructure](/content/blog/ai-critical-infrastructure-transformation/index.html): Explore how AI can transform critical infrastructure and lower the cost of personalization. (716 words) - [Knowledge Security Platform for HR & Legal Teams | Knostic](/content/departments/hr-legal/index.html): Keep salaries, whistleblower notes, and case files confidential. Knostic checks role and context before every AI reply, so sensitive people data stays sealed. (337 words) - [Primer: How to Spot and Analyze Malicious VS Code Extensions](/content/blog/how-to-spot-malicious-vs-code-extensions/index.html): Practical methods to identify, inspect, and defend against compromised IDE extensions that turn developer tools into an attack vector (417 words) - [From .env to Leakage: Mishandling of Secrets by Coding Agents](/content/blog/claude-cursor-env-file-secret-leakage/index.html): Claude Code and AI coding assistants automatically load .env secrets without disclosure. Learn how they leak API keys and how to protect your credentials. (849 words) - [What to Expect When You're Expecting Your GenAI Baby](/content/blog/what-to-expect-when-youre-expecting-your-genai-baby.html): Many of us are scrambling to leverage GenAI, but we are often not aware of the many risks that may arise. As we undergo this journey, it would be helpful t (582 words) - [OpenAnt: Read the LLM Vulnerability Paper](/content/blog/openant-read-the-llm-vulnerability-paper/index.html): Knostic's OpenAnt, al eading open-source tool that combines static analysis and LLM reasoning is now a paper. (211 words) - [Simulated LLM Recon for Pentesters | Knostic](/content/the-genai-knowledge-security-platform/simulated-llm-recon-pentesters/index.html): Let red teams see what Copilot can leak for a non-admin user. Knostic simulates AI reconnaissance and proves real gaps execs can’t ignore. (353 words) - [Knostic Security Program](/content/security/index.html): Knostic ensures enterprise-grade security with strong encryption, access controls, and incident response. (495 words) - [Knowledge Security Platform for Prod & Engineering | Knostic](/content/departments/product-engineering/index.html): Build faster without leaking roadmap secrets. Knostic blocks unreleased features and API keys from LLM chats, guarding your competitive edge. (360 words) - [AI Data Sprawl Detection Solution](/content/ai-data-sprawl-detection-solution/index.html): Stop AI data sprawl before it spreads. Gain visibility, detect risks, and safeguard sensitive information in real time. (304 words) - [Insider Risk & Zero-Trust Verification | Knostic](/content/the-genai-knowledge-security-platform/insider-risk-zero-trust-verification/index.html): See if Copilot can bypass Zero-Trust walls by piecing together secrets. Knostic spots insider-risk vectors and shows you when segmentation fails. (330 words) - [Security Platform for AI Agents | Knostic Blog](/content/blog/index.html): Stay up to date with the latest research, news, and insights into AI agent security with the Knostic AI blog. (193 words) - [Update and Infect: How the SaassyCode Campaign Grew from Two Extensions to Nineteen](/content/blog/update-and-infect-how-the-saassycode-campaign-grew-from-two-extensions-to-nineteen.html): How one VS Code extension published clean, built an install base, then silently delivered malware via a routine update. (4,228 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives - [AgentSite Network](https://agentsite.network/network.html): Public index of AgentSites and their machine-readable resources