-
September 8, 2026
-
September 8, 2026

For the past couple of years, most conversations about AI security have centered on the model. Is it hallucinating? Can it be jailbroken? Was it trained on sensitive data? These are reasonable questions, but they miss where the real exposure is building up fast.
True, the model may provide the intelligence, but an enterprise agent derives its practical power from a broader agentic fabric: instructions, memory, connectors, MCP servers, skills, hooks, and sub-agents that intersect with the employee endpoint and extend into enterprise and cloud systems.
I recently did a webinar with Black Hat’s Steve Paul, where we examine the agentic fabric emerging across employee endpoints, the external and internal threats it introduces, and why traditional endpoint security cannot adequately govern it.
Want to see how these risks play out and what security teams can do about them? Read on or watch the full webinar here:

The agentic fabric is the interconnected set of components on the endpoint that defines how an agent reasons, retains context, accesses systems, extends its capabilities, and delegates work. This includes:
The agentic ecosystem is evolving at an unprecedented pace, with new frameworks, components, and capabilities released almost continuously. Every new version expands what agents can do, such as running MCP servers, using skills, launching browsers, navigating the local computer, and interacting with more systems. This means the attack surface is continuously expanding and changing, making it challenging for security teams to keep up.
Unlike a traditional software supply chain, where a package at least goes through some CI/CD and dependency-scanning gate, an agent can be told mid-conversation to install a skill, connect to a new MCP server, or fetch a script. The agent will often comply, especially if the instruction is framed as coming from the user or from trusted-looking content it just read (a webpage, a PDF, an email). And since no one vets and governs (and in some cases, even has visibility) into these agentic fabric components, the agent might be invoking a tool that seems legitimate but is actually malicious or causes a risky outcome.
Threats generally fall into two categories:
Adversarial threats: Prompt injection, malicious skills, compromised MCP servers, credential theft, and supply-chain attacks intended to manipulate the agent.
Autonomous failures: The more overlooked category, where agents independently take unsafe actions because they misunderstand intent, exceed their authorized scope or go rogue, or use excessive permissions.
A well-known example of a rogue agent involves a Cursor agent working on a staging task that used an overly permissive token to delete a production database volume and its associated backups. The infrastructure provider ultimately recovered the data, but the incident disrupted customer operations and forced the company to reconstruct recent transactions manually.
Human oversight is less effective than expected. Research from Anthropic found that developer approval of Claude Code permission prompts at 97%, and production data showed serious unintended harm occurred in 6.3% of manually-approved sessions versus 2.4% of sessions run under automated review.This suggests that repetitive approval requests can create habituation, making manual confirmation a weak control for frequent agent actions.
There’s also composability risk. Individually, an instruction file, a skill, and an MCP connector might each pass a security review. But agentic fabric risk is often combinatorial: - a skill that shells out to the filesystem, paired with a memory store that persists across sessions, paired with a connector that has broad OAuth scope, creates an attack surface none of the three components has alone.
Why Traditional Endpoint Security Fails to Protect the Agentic Fabric on the Endpoint
Traditional endpoint security is designed to monitor processes, files, network connections, and system behavior. It can detect malware, suspicious command execution, privilege escalation, and other familiar indicators of compromise.
But AI agents don't behave like traditional software. They are dynamic, goal-driven systems whose actions depend on context. AI agentic risk often occurs inside legitimate applications and approved workflows, without producing any conventionally malicious endpoint behavior.
Traditional controls may observe individual parts of this sequence: a file read, a process execution, a network connection, or a tool invocation. What they generally lack is the agent-specific context needed to connect those events and determine whether the resulting action was intended, appropriate, and policy-compliant.
Protecting the agentic fabric therefore requires controls that understand the agent’s instructions, memory, skills, MCP connections, hooks, permissions, and execution flow. Endpoint security remains necessary, but it protects the environment around the agent, not the logic, context, and delegated authority operating inside it.
Security teams are struggling to keep pace with the rapid adoption of AI agents because of:
Securing the agentic endpoint requires a progression: discover the fabric, assess its components and combinations, define granular guardrails, enforce them consistently, and evaluate agent behavior at runtime. Backslash maps every agent's full context layer, analyzes every component and combination, identifies risks, enforces policies, and infers intent before and during runtime.
What does this protection look like in practice? Watch the full webinar.
Backslash Security is the Agentic AI Endpoint Security platform. We enable enterprises to discover, govern, and protect the agentic AI fabric - every AI agent, MCP server, and Skill running on employee endpoints - securing agentic AI at enterprise scale and business velocity.