logo

Open-source tool Sage puts a security layer between AI agents and the OS

ID: b792290c-57ea-5813-8948-ca21e0ab673d

STIX ID: report--b792290c-57ea-5813-8948-ca21e0ab673d

Feed Name: Help Net Security

Date Published: 2026-03-09

Date Updated: 2026-04-28

Author: Anamarija Pogorelec

...
...

This article describes Sage, an open-source Agent Detection & Response (ADR) project that inserts interception hooks into AI agent platforms (Claude Code, Cursor/VS Code, OpenClaw) to vet tool calls—Bash commands, URL fetches, and file writes—using URL reputation, local YAML heuristics, package supply-chain checks, and plugin scans; it preserves most data locally while optionally sending hashes to reputation APIs. The piece also references Gen Threat Labs research highlighting a large number of internet-exposed AI agent instances and a percentage of malicious skills, and provides installation and packaging details for supported platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.