Security platform for AI agents
CydraShield
CydraShield discovers agents, models, MCP servers, tools and permissions, then continuously identifies risky behaviour and policy violations. Each agent receives an explainable Agent Risk Score so security teams can prioritise what to fix.
CydraShield
What CydraShield answers
Discover every agent, understand its authority and score its risk.
What agents do we have?
An inventory of agents, versions, owners, models, MCP servers and tools, fed by connectors.
What can each agent do?
Agent identities and delegated permissions mapped into the Agent Security Graph.
Which agents matter most?
The Agent Risk Score combines production access, sensitive data, internet exposure, code execution, approval gaps, persistent memory, untrusted MCP tools and weak authentication, adjusted for active threats and controls in place.
What should we do now?
Findings with owners, approval controls for risky actions and a kill switch when an agent must stop.
Capabilities
CydraShield capabilities and status
Status reflects the current proof-of-concept build.
- Available
Agent inventory and ownership
Register agents, versions and accountable owners in one inventory.
- Beta
MCP server and tool discovery
Enumerate MCP servers and their tools through the MCP tools/list interface, with SSRF safeguards.
- Available
Model inventory (connector data)
Catalogue the models agents use, populated from mock OpenAI and Anthropic connectors.
- Preview
Live model discovery from provider APIs
Read model and assistant inventories directly from OpenAI and Anthropic accounts.
- Available
Prompt and activity logging
Record agent activity as metadata and content hashes by default, with redaction.
- Available
Agent identity and permission mapping
Give each agent a unique agent:// identity and map its delegated permissions.
- Available
Agent Risk Score (ARS)
Explainable 0–100 risk score with factor evidence, control credits, history and what-if analysis.
- Available
Secrets detection
Detect credentials and keys in agent inputs, outputs and tool parameters.
- Beta
Prompt-injection monitoring
Deterministic lexical and structural detection of direct and nested injection attempts.
- Available
Human approval controls
Route consequential actions to named approvers with expiry and anti-replay binding.
- Available
Agent kill switch
Suspend or revoke an agent and its credentials, stopping in-flight actions.
- Available
Tamper-evident audit trail
Hash-linked, signed evidence records with verification of the whole chain.
- Available
Findings and investigations
Triage, assign and resolve security findings about agents, tools and identities.
- Beta
Behaviour and action monitoring
Telemetry explorer with rate-anomaly detection on agent actions.
- Available
- Implemented, tested and demonstrable in the current proof-of-concept build.
- Beta
- Implemented and demonstrable, with documented limitations.
- Preview
- Interface or mock implementation behind a real contract; live integration not yet enabled.
- Roadmap
- Not built in this phase. Shared platform foundations are in place.