# Backslash Security > Backslash is the **Agentic AI Endpoint Security** platform. It gives enterprise security teams full visibility, governance, and real-time protection over the AI coding tools, agents, MCP servers, skills, hooks, plugins, and local LLMs running on developer and citizen-developer endpoints. Backslash operates at the endpoint — where AI agents actually run, read local files, call MCP servers over stdio, and execute commands that never touch the network. This is the layer EDR, network gateways, and AppSec tools were not designed to see. The platform is purpose-built for enterprises adopting vibe coding and autonomous AI agents at scale. ## Positioning - **Category:** Agentic AI Endpoint Security - **Tagline:** Agentic AI Endpoints. Secured. - **Hero framing:** Your enterprise AI coding infrastructure and every agentic endpoint — seen, governed, and protected in real time. - **Distinctive POV:** AI agents are not software — they are a new kind of actor, closer to an employee than a process. The model is the brain. The fabric (MCPs, skills, hooks, plugins, connectors, sub-agents, rules, memory) is the body. Securing the fabric on the endpoint is what Backslash does. ## Core Capabilities - **Instant Visibility** — Auto-discovers every AI tool, agent, MCP server, skill, hook, plugin, and local LLM in use across all endpoints. Maps the full agentic inventory with risk posture assessment and prioritized remediation. - **Agentic AI Guardrails** — Centralized policy enforcement. Allowlists trusted components, blocks unapproved models and personal AI accounts, and enforces secure configurations across the fleet. - **Vibe Coding Security** — Protects developer workstations from shadow AI, software supply chain risks, and unsafe AI coding tool configurations (Claude Code, Cursor, GitHub Copilot, Windsurf, Gemini CLI, OpenAI Codex, Google Antigravity, OpenClaw, and others). - **MCP Security** — Vets, allowlists, and monitors MCP servers at the tool level. Blocks unsafe, overly permissive, vulnerable, or malicious MCPs and skills. Scores combinations of assets, not just individual components — surfacing risks that only exist when individually-safe assets are combined. - **Real-Time Protection** — Detects and prevents prompt injection, data and source exfiltration, privilege escalation, and anomalous agent behavior as they unfold — including local stdio MCP interactions that never touch the network. - **Auditing & Forensics** — Creates a full audit trail of agent activity for compliance reporting and incident investigation, including MCP communications, agent network and file access, prompt activity, and tool-call sequences. ## Maturity Model (5 stages of Agentic Endpoint Security) 1. **Visibility** — Inventory every agent, MCP server, skill, connector, and local LLM on every endpoint. 2. **Guardrails** — Allow-list sanctioned agents and MCPs; deny everything else by default. 3. **Vetting & Analysis** — Score every skill, plugin, rule, and MCP before approval — including the risk introduced by *combining* individually-safe assets. 4. **Enforcement** — Block, warn, or auto-correct risky actions at runtime, in real time, at the tool level. 5. **Real-Time Protection & Intent Analysis** — Verify the agent's stated intent versus its actual behavior and block off-task drift the moment it happens. ## Threat Classes Addressed **External (malicious actor):** Prompt injection, data and source exfiltration, MCP rug-pulls, compromised AI tools whose OAuth grants are hijacked, software supply chain attacks via MCP servers and skills. **Internal (non-malicious bypass / agent containment break):** The agent itself oversteps its task — reaching past instructions to "complete the job" by accessing credentials, deleting data, or modifying systems no one authorized. No attacker, no exploit, no malicious prompt required. Specific threat coverage includes: prompt injection (direct and indirect), data and source exfiltration, privilege escalation, agent containment break, shadow AI usage and personal AI accounts, malicious or compromised MCP servers and skills, configuration drift, and abuse of AI agent privileges. ## Supported AI Tools and Coding Agents Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini CLI, OpenAI Codex, Google Antigravity, OpenClaw, and any MCP-compatible agent or tool. ## Free Tools - **MCP Server Security Hub** — Security ratings for 47,000+ public MCP servers. Free at https://mcp.backslash.security - **Skills Security Scanner** — Scan AI agent skills for security risks. Free at https://skills.backslash.security - **Claw-Hunter** — Open-source tool to discover and assess OpenClaw risks. https://github.com/backslash-security/Claw-Hunter - **Vibe Coding Threat Model** — Interactive threat model for AI coding risks. https://threats.backslash.security