Knostic logo

Knostic

Category:

Security Platform for Coding Assistants and MCP - Knostic

What is Knostic?

Knostic is an AI security platform that tames shadow AI and protects autonomous coding assistants like Copilot or Cursor. By blocking data leaks and malicious commands in real time, it gives security teams complete risk control without slowing down developer velocity.

Features

Overview

Knostic is an AI security platform for shadow AI discovery and coding assistant protection. It targets AI agents, MCP servers, IDE extensions, and agent rules that widen a company’s attack surface.

Its commercial product for developers, Kirin, inspects MCP connections and monitors extensions and plugins inside supported IDEs. It also scans agent rules for hidden malicious instructions.

For governance teams, Knostic scans logs, APIs, and traffic patterns to build an inventory of AI tools. The inventory shows which departments use them and what data they can reach.

Knostic also publishes open source tools, including the OpenAnt vulnerability scanner and OpenClaw plugins. Gadi Evron and Sounil Yu founded the company in 2023, and SINET named it a 2025 SINET16 Innovator.

Pricing

Knostic does not publish plan names, prices, or usage limits. Commercial access runs through a sales-led demo, and the reviewed pages list no free trial. OpenAnt is free under the Apache 2.0 license, and Knostic offers free scans for open source projects. The OpenClaw plugins are also open source on GitHub.

* Disclaimer: Please note that pricing information may not be up to date. For the most accurate and current pricing details, refer to the official website.

Key Features

  • ✓

    Shadow AI discovery from logs, APIs, and traffic patterns

  • ✓

    Real-time MCP connection inspection for misconfigurations and unauthorized access

  • ✓

    Dependency scanning for known CVEs and typosquatted packages

  • ✓

    Policy drift detection for insecure configuration changes

  • ✓

    Blocking of destructive commands such as rm -rf

Use Cases

01

Mapping AI Usage by Department

Security teams preparing for an audit can see which departments use which AI tools. Knostic builds this inventory from logs, APIs, and traffic patterns.

02

Restricting Unapproved MCP Servers

Teams piloting AI coding assistants can limit developers to approved MCP servers. Kirin flags misconfigured or unapproved endpoints as connections occur.

03

Screening Risky Editor Extensions

Knostic documented CodeRelay, a campaign of 13 malicious VSIX packages across 12 VS Code extensions. Kirin monitors extensions and plugins for the same class of risk.

04

Scanning Open Source Repositories

Maintainers can run OpenAnt locally or request a free scan from Knostic. Only findings that survive both detection and attack stages appear in the report.

05

Guarding OpenClaw Agents

Teams running OpenClaw agents can add openclaw-shield to redact secrets and PII from tool output. It also requires a gate check before shell commands or file reads.

Strengths & Weaknesses

Strengths

+

One product covers MCP connections, extensions, plugins, and agent rules.

+

Kirin also scans agent rules for hidden malicious instructions.

+

A single dashboard consolidates MCP usage, plugin blocks, and dependency findings.

+

Knostic publishes its own threat research, including the CodeRelay extension campaign.

+

OpenAnt’s Apache 2.0 license lets teams inspect and run the scanner themselves.

Weaknesses

–

Plans, prices, and usage limits are not public, and access starts with a demo.

–

Knostic does not detail how its free tools differ from the paid platform.

–

The OpenClaw plugins target one agent framework, and Knostic reported a non-functional layer on v2026.1.30.

–

Documented Kirin support covers Cursor, Copilot, Claude Code, and Windsurf, not other environments.

Who Is This For?

●

Security and AppSec leaders: teams that need an inventory of shadow AI and policy control over agent access.

●

Engineering managers: leads rolling out AI coding assistants who want extension and MCP oversight.

●

Governance and compliance teams: reviewers who need audit trails and department-level views of AI tool usage.

●

Open source maintainers: developers who want a free LLM-based scanner or OpenClaw guardrails without a sales process.

Frequently Asked Questions

Does Kirin run only inside the IDE?

Kirin works at the IDE runtime layer. Knostic also states it can connect to CI/CD pipelines to enforce MCP policies during builds.

How does Knostic detect unsanctioned AI tools?

It analyzes logs, API traffic, and integration points. This includes tools that nobody formally approved.

How does OpenAnt differ from Kirin?

OpenAnt is a separate open source vulnerability scanner. Kirin is Knostic’s commercial product for coding assistants and MCP, which is its core focus.

How does OpenAnt reduce false positives?

Stage one detects candidate flaws. Stage two attempts to attack them, and only surviving findings are reported.

Which programming languages does OpenAnt scan?

It supports Python, JavaScript, TypeScript, Go, PHP, and C/C++.

Is OpenAnt ready for production use?

Knostic says it began as a research project. Some features remain in beta, so a pilot run is sensible.

Does Kirin slow developers down?

Knostic says Kirin surfaces risks and fixes without interrupting work. No independent performance data was found.

Does Knostic replace existing application security tools?

Knostic says its focus is coding agents, not application security. Most teams will likely keep conventional scanners alongside it.

Kirin supports Cursor, GitHub Copilot, Claude Code, and Windsurf. Microsoft 365 Copilot is supported with controls against sensitive data oversharing. Knostic states Kirin can connect to CI/CD pipelines. The OpenClaw plugins and OpenAnt are separate open source tools.

Integrations