Open-source tool Sage puts a security layer between AI agents and the OS
ID: b792290c-57ea-5813-8948-ca21e0ab673d
STIX ID: report--b792290c-57ea-5813-8948-ca21e0ab673d
Feed Name: Help Net Security
This article describes Sage, an open-source Agent Detection & Response (ADR) project that inserts interception hooks into AI agent platforms (Claude Code, Cursor/VS Code, OpenClaw) to vet tool calls—Bash commands, URL fetches, and file writes—using URL reputation, local YAML heuristics, package supply-chain checks, and plugin scans; it preserves most data locally while optionally sending hashes to reputation APIs. The piece also references Gen Threat Labs research highlighting a large number of internet-exposed AI agent instances and a percentage of malicious skills, and provides installation and packaging details for supported platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
