At a glance
- Approving an AI plugin means checking provenance, identity, permissions, execution rights, data destinations and auditability before the component ever runs.
- MDM enrollment and endpoint detection tooling govern applications and processes; they do not resolve which agent, Skill or MCP server acted.
- Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector on an endpoint.
- Backslash Security blocks risky agent actions inline before execution, including credential access, privilege escalation and data sent to unapproved destinations.
- Backslash Security publishes Claw-Hunter, an open-source tool for discovering and assessing OpenClaw risks.
Backslash Security
Published:
Approving an AI plugin on an employee laptop comes down to fifteen checks across five questions: what the component actually is, whose identity it runs under, what it is permitted to execute, where data can travel, and what record survives afterward. A "plugin" in this context is rarely a packaged application. It is usually an Agent Skill — packaged instructions and scripts that extend what an AI agent can do, executing with the user's own permissions, and often just a markdown file on the machine — or an MCP server, a connection an agent can act through using the Model Context Protocol, or a hook that fires before or after an agent action, or a rules file such as AGENTS.md or CLAUDE.md carrying standing instructions the agent reads on every run. Each of the fifteen criteria below is written to be answerable with evidence from the endpoint itself, not from a vendor questionnaire.
The incumbent controls on that laptop were bought for different jobs. MDM platforms such as Intune and Jamf are bought to enroll devices, enforce configuration and govern which applications install. EDR — endpoint detection and response, the established endpoint layer with broad general-purpose coverage and an agent already on the machine — is bought to catch malicious processes, files and known-bad behavior. Neither resolves which agent, Skill or MCP server caused a given action, which is the specific question an approval decision turns on. Backslash Security works at that layer: it covers AI coding agents including Claude Code, Cursor, Codex, Devin, GitHub Copilot and Antigravity, assesses the components running beneath them, and enforces policy on the host. The criteria that follow are the questions a reviewer has to answer for each component in 2026, now that agents, Skills and MCP servers run on ordinary employee laptops.
What exactly counts as an AI plugin on an employee laptop?
What exactly counts as an AI plugin depends on what you mean by "plugin," because the word is doing two different jobs on a modern laptop. It can mean a packaged add-on installed into a host application, or any component that extends what an AI agent is able to do once it is running. Both are review surfaces, and they behave differently.
The host-application add-on. This is the familiar object: an extension installed into an IDE or a desktop application, or a connector that links an application to an external service. A GitHub Copilot or JetBrains AI extension inside an editor is a clear example. It has a name, a publisher, and a version, and it usually appears in a software inventory.
The agentic component. This is anything an agent reads or calls at runtime to extend its reach, and much of it is created after install rather than shipped with it:
- MCP servers and MCP tools — endpoints exposed through the Model Context Protocol; each server is a connection an agent can act through, and each tool is a discrete capability behind it.
- Agent Skills — packaged instructions and scripts that tell an agent to read a file, call an API, or run a shell command.
- Hooks — triggers that fire before or after an agent action.
- Rules files such as AGENTS.md or CLAUDE.md — files carrying standing instructions an agent reads on every run.
This piece uses the agentic-component meaning and treats the host-application add-on as one entry inside it. The review surface therefore spans agents and local models, MCP servers and tools, Skills, hooks, rules files, plugins and connectors, installed by employees on their own endpoints and running under their own identities. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint.
Which 15 criteria should an approval checklist actually test?
This section narrows the approval question to one case: an employee asking to run an AI component on a managed laptop — an agent, a plugin, an Agent Skill (packaged instructions and scripts that extend what an agent can do), an MCP server (a Model Context Protocol connection through which an agent reaches external tools and data), a hook (a trigger that fires before or after an agent action), or a rules file such as AGENTS.md or CLAUDE.md carrying standing instructions the agent reads on every run. Each criterion names what it tests and the evidence that closes it.
| # | Criterion | What it tests | Evidence that satisfies it |
|---|---|---|---|
| 1 | Component type | Which class of component this is | Inventory entry naming agent, model, Skill, MCP server, hook, rules file, plugin or connector |
| 2 | Provenance | Publisher, repository, signing | Verified source and maintainer record |
| 3 | Update mechanism | Whether it self-updates silently | Documented version pinning or update policy |
| 4 | Requested permissions | Scopes the component asks for | Enumerated permission map |
| 5 | Identity binding | Corporate single sign-on versus a personal login | Entra ID or Okta session, not a private account |
| 6 | Data destinations | Where outputs and context are sent | Allowlisted endpoints only |
| 7 | Model and inference location | Hosted service or local runtime | Named model and hosting location |
| 8 | Secrets exposure | Reach into tokens, cloud credentials, Git configuration | Scoped credential access rather than broad read |
| 9 | Command execution | Ability to run shell commands with the user's own rights | Approved command list |
| 10 | File system scope | Folders readable and writable | Declared folder structure |
| 11 | Rules and hook footprint | Standing instructions installed alongside it | Reviewed rules file and hook contents |
| 12 | Tool surface | Tool descriptions an MCP server exposes | Reviewed tool manifest |
| 13 | Injection exposure | Whether it reads untrusted content that could carry hidden instructions | Documented content sources |
| 14 | Enforcement coverage | Whether a risky action can be stopped at the moment it is attempted | Documented control acting at execution time |
| 15 | Traceability | Reconstruction from prompt to agent to tool call to outcome | Retained run traces |
Criteria 1 through 7 are answerable at intake. Criteria 8 through 13 require inspecting the component itself. Criteria 14 and 15 describe the controls wrapped around it. For criterion 15, Backslash Security states that it automatically generates audit evidence for EU AI Act, NIS2, DORA and SOC, which supplies the record a reviewer or auditor asks for.
How do the 15 criteria compare across identity, data, action and context risk?
The 15 criteria compare most usefully when sorted across four risk dimensions — identity, data, action and context — because each dimension asks a different question about the same component and catches a different class of failure. "Plugin" here covers the whole agentic layer an employee installs: MCP servers (Model Context Protocol connections an agent acts through), Agent Skills (packaged instructions and scripts that run with the user's own permissions), hooks (triggers that fire before or after an agent action), and rules files such as AGENTS.md or CLAUDE.md that carry standing instructions an agent reads on every run.
Set the dimensions before scoring anything. Identity becomes decisive wherever employees sign in with personal accounts on corporate machines. Data becomes decisive on hosts holding source code, tokens and customer records. Action becomes decisive the moment a component can execute shell commands. Context becomes decisive because an agent acts on text it reads, so the trust level of the repositories, issues and pages it touches is itself an approval question.
| Risk dimension | What the criteria examine | Failure it catches | Evidence an approver needs |
|---|---|---|---|
| Identity | Which account authorized the component, token scope, personal versus corporate credentials | Shadow AI — unapproved tools running under a private login | Inventory entry tying each component to an identity in Entra ID, Okta or Active Directory |
| Data | Filesystem paths, repository access, egress destinations, secret handling | Silent exposure of source code, API tokens or Git configuration | Declared read and write scope, plus a trace of destinations actually reached |
| Action | Command execution, privilege escalation, write access to dev and production systems | A rogue agent taking steps nobody requested | Policy showing which actions are allowed, denied or stopped before execution |
| Context | Sources the agent reads: rules files, repositories, documents, web content | Prompt injection — hidden instructions in content the agent reads | Provenance of every instruction source and a record of what the agent consumed |
Where that evidence comes from depends on the layer you review at.
| Option | Layer it works at | Differentiator for this review |
|---|---|---|
| Backslash Security | On the host, at the agentic layer | Agentless discovery — collecting information without permanently installed software — paired with on-host enforcement, so an approved policy is applied where the agent executes |
| Zscaler | Network layer | Raised by buyers as an alternative when they already own network-layer security |
| Agentless-only agent-governance tools | No endpoint deployment at all | Fastest possible path to first visibility |
If deploying endpoint software is genuinely blocked — contractor fleets, unmanaged hardware, restrictive change windows — a network-layer or agentless-only review remains a reasonable call, and the inventory it produces is still worth building an approval record on.
Why do endpoint and identity controls alone miss agentic plugin risk?
When endpoint and identity controls are the only governance covering AI plugins on employee laptops, the agent-to-tool call passes beneath every one of them. Each layer was built to watch a different object, and none of those objects is the agent.
Device management — the MDM layer that enrolls machines, pushes configuration profiles, and inventories installed applications — reports software that arrives through an installer. An Agent Skill is frequently just a markdown file dropped into a user directory, and a rules file such as AGENTS.md or CLAUDE.md is standing text the agent reads on every run. Neither produces an install event.
Endpoint detection and response tooling observes processes, files, and known-bad behavior. It can record that an interpreter opened a credential store; the prompt, the Skill, and the MCP server — Model Context Protocol being the protocol agents use to reach external tools and data — that caused the call sit above the process boundary where that telemetry stops.
Identity reviews have the same shape. The agent authenticates with the employee's own token through the organization's single sign-on, so its tool calls certify as ordinary approved access during an entitlement review.
| Keep doing this | Watch out for | Mitigation |
|---|---|---|
| Device enrollment and app inventory | Components delivered as files or config, never as installs | Add continuous discovery of agents, MCP servers, Skills, hooks, and rules files |
| Endpoint detection telemetry | Alerts name a process without the component that triggered it | Capture the agent run itself, so responders can attribute the call |
| Identity and access certification | Agent activity inherits a legitimate human token | Govern which agentic components may act under that identity |
| Network-layer controls | Network and host are different enforcement points | Add enforcement at the host, where the agent executes |
Backslash Security works at that agentic layer on the host, resolving which agent, Skill, or MCP server produced an action so the activity can be governed under policy. Policies are written per team and risk profile rather than applied uniformly, so each team works within the components approved for it.
How should a security team run the approval workflow end to end?
A security team can run AI plugin approval as a repeatable loop rather than a one-off review, because the agentic layer on an endpoint shifts every time an employee installs something new.
- Take the intake request in a structured form. Record what the employee wants to run — the agent, the MCP server (Model Context Protocol is how agents connect to external tools), the Skill (packaged instructions and scripts that extend an agent, executing with the user's own permissions), the business purpose, and the identity it will run under.
- Discover what is already on the fleet. Judge the request against reality rather than a wishlist. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint, turning an approval queue into a reconciliation exercise against a live inventory.
- Assess against your published criteria. Score risk posture per component — permissions requested, destinations reached, and any rules file (standing instructions an agent reads on every run, such as AGENTS.md or CLAUDE.md) shipped alongside it.
- Make the governance decision explicit. Allowlist approved components, denylist risky ones, and write per-team policies so different teams can carry different thresholds without separate processes.
- Enforce where the agent executes. Backslash Security applies policy on the host at the agentic layer, at the moment an agent attempts an action, so an approval decision is binding rather than advisory.
- Keep the record for what comes next. Retain audit and tracing data of agentic activity so an investigator can reconstruct a specific run, and so approvals can be revisited when a component's behavior changes.
What evidence and review cadence keep an approved plugin list trustworthy?
An approved plugin list stays trustworthy only when dated evidence sits behind every entry and a published review cadence forces each one to be re-earned. Approval records age faster than the components they describe: a version bump, a widened permission scope, or an edit to a rules file — a file on a machine or in a repository carrying standing instructions an agent reads on every run — can change what an approved component does without changing its name.
What should trigger a re-review?
- A version change in an agent, MCP server, Skill, plugin, or connector.
- A permission or scope expansion: a new filesystem path, credential, or outbound destination.
- A change of maintainer or source repository.
- An edit to an attached hook or rules file after approval was recorded.
- Elapsed time since the last review, whether or not anything visibly changed.
What should every record carry?
A named human owner, the approval decision and its date, any policy exception granted, and every inventory count with the date it was read. A count without that date is not evidence; it is a snapshot someone will quote next quarter as if it were still true.
Backslash Security supports that cadence by continuously discovering the agents, models, MCP servers, Skills, hooks, rules files, plugins and connectors running across all employees and endpoints, enforcing allowlist and denylist policy against that live picture, and collecting audit and tracing data an investigator can use to reconstruct what an agent actually did.
Latio's 2026 AI Security Market Report named Backslash Security an Endpoint AI Security Leader, a badge awarded to vendors demonstrating the most in-depth controls for AI on the endpoint, including permission mapping, folder structures, approved commands, and runtime controls for MCPs and Skills.
Frequently Asked Questions
What should an approval checklist cover for AI plugins on employee laptops?
An approval checklist for AI plugins on employee laptops has to cover the component itself and everything it can reach, because a plugin, an Agent Skill, or an MCP server is rarely a self-contained piece of software. MCP, the Model Context Protocol, is the protocol agents use to connect to external tools and data sources, so each MCP server is a live connection an agent can act through. Practical criteria include:
- Publisher provenance and whether the component is pinned to a known version
- The identity it runs under — corporate account or a personal login
- Which files, repositories, and credentials fall inside its reach
- Outbound destinations it may send data to
- Whether it can execute shell commands or install further components
- How it updates, and whether an update re-triggers review
- What audit record exists after it runs, and how approval is revoked
Why is an Agent Skill harder to approve than a normal application?
An Agent Skill is a packaged set of instructions and scripts that extends what an AI agent can do — in practice often just a markdown file sitting on the employee's machine. It can tell an agent to read a file, call an API, or run a shell command, and it executes with the user's own permissions, which means it inherits whatever access that person already holds. There is no installer, no signature, and no app-store gate, so the usual software-approval workflow never fires.
Backslash Security offers a free AI Endpoint Exposure Assessment that is agentless, read-only, and retains no data — agentless meaning information is collected without leaving software permanently installed on the endpoint. It is distributed through existing MDM tooling, so no separate rollout is needed to get a first inventory. For organizations assessing a specific exposure, Backslash Security also publishes Claw-Hunter, an open-source tool for discovering and assessing OpenClaw risks, and operates a free Skills Security Scanner that scans AI agent Skills for security risks.
Which AI coding agents should fall inside the approval scope?
Any agent that can read a repository, call a tool, or execute a command belongs in scope, which in most engineering organizations means the coding agents already in daily use. Backslash Security covers AI coding agents including Claude Code, Cursor, Codex, Devin, GitHub Copilot, and Antigravity, along with the MCP servers and Skills layered on top of them. Scope should also include local model runners and desktop assistants, since those connect to the same tools and credentials from the same machine.
About this article
Backslash Security publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Backslash Security before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-07