Security for AI agents harnesses, SKILLs, MCPs, and plugins
Take control of your AI agent assets
Your teams install SKILLs, MCPs, and plugins faster than any review process can follow. Optimus Labs discovers each asset, maps what it can reach, inspects it, and enforces policy while it runs.
Every install changes the code and the context an agent can touch. Optimus Labs tracks it continuously, so no single run ever combines sensitive data, untrusted input, and external action.
Four questions
Can your security team answer these today?
01
What is running?
Can you name the agents, MCP servers, SKILLs, and plugins in use today?
02
Where did it come from?
Can you trace publishers, repositories, updates, and configuration changes?
03
What can it reach?
Do you know which agents combine untrusted input, sensitive data, and external action?
04
What happens when it acts?
Can you stop a risky tool call before it executes?
AI agents and assets Optimus Labs secures
Agent harnesses, SKILLs, MCP servers, plugins, hooks, and inference gateways






















Lethal Trifecta makes every AI agent vulnerable
Named by Simon Willison, the Lethal Trifecta is the danger of an AI agent combining access to sensitive data, exposure to untrusted content, and a way to send data out.
When all three combine, one prompt injection can exfiltrate data or trigger unauthorized action. Optimus Labs helps you make sure no single agent ever holds all three at once.
Lethal Trifecta coined by Simon Willison (opens in new tab).
Threat research
Original research, published in the open
We investigate real attacks on AI agent assets, publish the evidence, and release the tools we build to investigate them.
Open-source incident response
GrokPatrol
Find out whether Grok Build CLI collected and queued your repositories for upload, including secrets deleted from the working tree but still present in Git history.
Investigate your exposureThe team
The people behind Optimus Labs
Backed by
Why this matters now
Agents are moving into enterprise workflows faster than the controls needed to govern their access and actions.
74%
of leaders expect at least moderate agent use by 2027. Only 21% report mature agent governance.
Adoption is scaling faster than the controls meant to govern it.
Deloitte, April 2026150K+
agents forecast in the average Fortune 500 enterprise by 2028. Only 13% believe their governance is suited to that scale.
Agent sprawl is coming whether security teams are ready or not.
Gartner, April 20261,708
credential-leakage issues found across 17,022 analyzed agent SKILLs.
Bundled SKILLs leak live tokens and keys straight from public repositories.
Academic research, June 2026Complete your security stack
EDR watches processes. AppSec watches pipelines. Both read agent asset activity as innocuous user behavior. Optimus Labs watches the new, dynamic attack surface that AI agent assets create.
EDR
Processes
Monitors endpoints
AppSec
Pipelines
Monitors DevSecOps workflows
Optimus Labs
Agent assets
Watches the attack surface others miss
What Optimus Labs does
From the moment an agent is installed to the moment it acts, one sensor on the endpoint.
AI supply chain security
Supply chain risk does not end at the package scan
A trusted SKILL can be hijacked after review. A plugin update can change what it does. An MCP server configuration can grant excess access. Untrusted input can steer a legitimate tool. Optimus Labs connects the provenance and posture of every agent asset to what the agent later attempts.
Find every agent asset, score its risk, enforce at runtime
A lightweight, agentless sensor protects agent assets wherever they run, with deep endpoint coverage where most enterprise agent assets execute. Install the sensor, review the inventory, turn on policies.
Connect
Deploy through the MDM you already run in about two minutes. The lightweight sensor does not continuously consume compute. No code changes, no proxy, nothing added to the request path.
Discover
Surface the SKILLs, MCP servers, plugins, hooks, and inference gateways your teams run, across managed endpoints and cloud VMs, and tie every asset to the identity and owner behind it.
Enforce
Score each asset's posture, watch its behavior for anomalies, and alert, justify, or block before the action takes effect.
From the field
What security leaders say
“AI agents are being adopted by engineers faster than most security processes can adapt. For us, the challenge wasn't enabling that adoption, but understanding what was actually running on developer machines and what those agents could access or do.
Optimus Labs gave us that visibility without forcing us to redesign how engineers work. Being able to discover agents, MCP servers, skills and their configurations at the endpoint gave us a much clearer picture of our real agentic attack surface and, more importantly, concrete findings we could act on.
What I have valued most is that it turns a fairly new and abstract security problem into something operational. Instead of trying to govern AI usage through assumptions or restrictive policies, we can see the actual risks, prioritize them, and work with engineering teams to improve the posture while still allowing people to experiment with these tools.”
Miguel FontanillaPlatform Eng Lead, European Freight Tech Leader“We leaned into AI-assisted development early and deliberately. We wanted the productivity gains, so we encouraged the experimentation. What concerned me was the flip side: shadow IT was quietly becoming shadow AI, and none of our existing tooling could see it. Agents run locally, on the workstation, configured by whoever set them up.
Optimus Labs closed that gap. We now have an inventory of the agentic tooling actually in use across our engineering fleet. The harnesses, the MCP servers, the skills and plugins, and how each one is configured, plus a backlog of findings with owners attached.”
Felipe OliveraSecurity Eng Lead, European Freight Tech LeaderQuestions we hear most
Break the Lethal Trifecta before it breaks your security
See every agent asset, what it can reach, and the risky combinations, then enforce policy before the action takes effect.




