Approval is only the start
An approved coding agent can gain new capabilities through MCP servers, skills and plugins. The original review may no longer reflect what the agent can do.
You approved the AI agent. Do you know what its added tools can reach? Identra discovers MCP servers, skills and plugins on macOS and Windows endpoints, checks agent tool calls against policy and records each run with the person behind it.
What security teams run into with MCP servers today, before a control is in place.
An approved coding agent can gain new capabilities through MCP servers, skills and plugins. The original review may no longer reflect what the agent can do.
Employees add tools as their work changes. Security teams can lose track of which servers, skills and plugins are present.
An agent with shell or file access can turn a mistaken instruction into a destructive action. Written usage rules alone do not stop that action.
When an agent does something unexpected, security needs to know who ran it, on which device and what happened.
Covered by Identra on macOS and Windows, tied to one identity and one timeline.
The same moment, played twice. Once without Identra, once with it.
A developer adds an MCP server and a skill to a coding workflow on a Mac.
Security's inventory lists the coding agent but misses the new additions.
During a cleanup task, the agent attempts a destructive shell command.
Security must piece together who ran the agent and what happened.
Identra discovers the coding agent, MCP server and skill on the developer's Mac.
With policy set to block, Identra denies the destructive shell command.
Protected-file controls on macOS can also deny the agent access to protected files.
The agent run is recorded with the developer, device, AI client and blocked outcome.
Bring MCP servers, skills and plugins into your endpoint AI inventory.
Have AI agent tool calls checked against your policy.
Deny destructive shell commands when blocking policy is active and protect file access on macOS.
Review agent runs with the user, device, AI client and allowed or blocked outcome.
QUESTIONS
Discovery gives you an inventory of MCP servers, skills and plugins. Enforcement applies to specific actions: AI agent tool calls are checked against policy, destructive shell commands can be denied, and protected-file access can be denied on macOS.
Deploy the Identra endpoint agent on macOS and Windows to discover coding agents, desktop AI apps, MCP servers, skills and plugins. Learn more about the endpoint platform.
Prompts to Codex and Claude Code are checked on the device before they are sent, and blocked when policy is active. Desktop AI composers get the same on-device checks.
Identra checks agent tool calls against policy and denies destructive shell commands when policy is set to block. This gives you specific controls for agent actions within existing coding workflows.
The endpoint agent runs on macOS and Windows. Protected-file access denial is a macOS capability.
Identra records the user, device, AI client and allowed or blocked outcome for AI agent runs. Where the person is known, endpoint activity joins browser and provider activity in one identity timeline.
KEEP READING
The terms, comparisons and essays behind this page.
A walkthrough with a security engineer.