Skip to content
Rush Commerce
AI & Automation4 min read

Noma pushes agent security to the laptop, the real blind spot

Noma extended agent discovery, access control, and AI-DR to employee endpoints — because MCP servers on a dev laptop run with the installer's credentials.

The scariest agent in your company is on somebody's laptop, and nobody wrote it down. Noma Security extended agent security and governance to the employee endpoint today, and the reason is stated plainly in the announcement: agents, MCP servers, and skills already running on employee laptops carry the same permissions and credentials as the people who installed them. That is not a hypothetical. That is your dev machine, right now, with a Stripe key in a .env file and an npm publish token in your keychain.

What actually happened

Noma's endpoint release lands three things. Discovery finds the agents, MCP servers, and skills already deployed on employee machines. Access control governs them through a Governed Registry, identity-aware policy, and tool- and action-level control. AI-DR — AI detection and response — baselines agent behavior at runtime and flags prompt injection, data leakage, malicious intent, tool poisoning, and scope violations. Each detector is tunable: monitor, alert, steer, block, mask the data, or route to a human.

The coverage list is the part that will look familiar: Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, OpenClaw, and GitHub Copilot. Enforcement runs through what Noma calls Open Enforcement, applied across agent hooks, AI and MCP gateways, SDKs, and existing EDR and MDM rather than a new agent on the box. Customers start from hundreds of AI-DR policies and protection profiles tuned by industry and agent type, built out of work with dozens of Fortune 500 security teams.

One honest note on scope: Agent Boundaries — business-defined limits on what an agent may do — is announced as planned for the endpoint, not shipping there today. Noma is backed by Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures, and SVCI.

Why endpoint agent security matters for your business

You are not buying this, and you still have the problem. Noma sells to Fortune 500 security teams. A six-person studio is not the customer. But the vulnerability does not scale down — it gets worse, because the laptop that runs your coding agent is also the laptop with production database credentials, the cloud CLI already logged in, and the deploy key. There is no separate ops box to hide behind.

Start with the inventory, because it costs nothing. Every engineer on your team should be able to answer two questions today: which MCP servers are configured on this machine, and which skills can run without a prompt. Read your own mcp.json and your skills directory. We have done this exercise and found servers nobody remembered adding, still holding a live token.

Agent hooks are the enforcement point you already own. Noma enforcing through hooks is a tell. Claude Code supports hooks natively — a PreToolUse hook is a script you write that sees every tool call before it runs and can refuse it. You do not need a platform to block rm -rf, an outbound POST to a domain you have never heard of, or a read of ~/.aws/credentials. You need forty lines of code and an afternoon.

Tool poisoning is the category most teams have not modeled. Everyone understands prompt injection in a web page by now. Fewer have thought about an MCP server whose tool description is the attack — a string the model reads and obeys, shipped in a dependency you installed once and never audited. Pin your MCP server versions the way you pin anything else you execute.

Scope violations are the failure you will actually hit. Not a nation-state. An agent doing a reasonable-looking thing in the wrong environment: migrating the production database because that is the connection string it found. Separate credentials per environment and give the agent the boring one.

Key takeaways

  • Noma extended agent discovery, access control, and AI-DR to employee endpoints on September 28
  • The stated premise: agents, MCP servers, and skills on employee laptops inherit the installer's permissions and credentials
  • Covers Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, OpenClaw, and GitHub Copilot
  • AI-DR detects prompt injection, data leakage, malicious intent, tool poisoning, and scope violations, tunable per detector
  • Agent Boundaries is planned for the endpoint, not shipping there yet
  • Small teams get most of the value free: inventory your MCP servers and skills, write a PreToolUse hook, split credentials per environment

If you cannot name every MCP server on your team's laptops, you cannot say what your coding agent is allowed to reach. We inventory the agent surface on a dev machine, write the hooks that refuse the calls that should never happen, and split credentials so an agent pointed at the wrong environment fails loudly instead of quietly. See how we set up agent guardrails, or tell us what your agent can currently touch.

Sources: Noma Security, PR Newswire.

  • #ai-security
  • #mcp
  • #ai-agents
  • #governance
  • #dev-tools
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.