IDE extensions, browser extensions, and AI-agent MCP servers execute with your developers' privileges — reading source, secrets, and traffic. PluginSec is the lightweight agent that inventories every plugin across your fleet, flags the malicious ones with our threat intel, and enforces an allowlist before they run.
Developers and AI agents install thousands of third-party plugins that run with high privilege on the endpoint — and your security team has zero visibility into them.
Full filesystem and shell access on activation. They read your source and secrets, and can run arbitrary code on install or silent update.
Read and modify all web traffic, steal session cookies and tokens, and inject scripts into every page your team visits.
The newest and least-monitored surface. MCP servers run as local processes with tool access — wide open to prompt injection, tool poisoning, and rug-pulls.
If it has an install command, it runs code on your endpoint. One brew install, cargo add, or go get can execute an arbitrary build or post-install script with the developer's privileges.
Security grew a Detection & Response category for every layer — EDR for endpoints, NDR for the network, XDR across them. The plugins and AI agents your developers run are a new, high-privilege layer none of those see. AIDR — AI Detection & Response — is the category for it.
Continuously inventory every plugin, AI-agent skill, and MCP server into a Plugin SBOM, and correlate each against our threat intel — returning a verdict: clean, suspicious, or malicious.
Enforce your allowlist on the endpoint — block, quarantine, or warn — before a risky plugin runs, with an audit trail on every decision. Visibility without response is just a report.
We track the attack techniques that target the plugin layer specifically — not generic malware signatures.
Plugins shipped to steal wallets, keys, and credentials from the moment they activate.
A trusted plugin silently auto-updates to a malicious version. We detect the drift.
Look-alike names and spoofed publishers that trick developers into installing the wrong thing.
Scope creep — a formatter that suddenly wants network, filesystem, and shell access.
Malicious MCP tool descriptions and payloads that hijack your AI agents.
Plugins that quietly ship secrets, cookies, and source to attacker-controlled endpoints.
Shadow MCP configs added to agents with no review. We surface every one.
The intel does the hard work in our cloud. Your endpoints only ever get a yes / no.
A lightweight sensor on every developer endpoint — macOS, Windows, Linux. Minutes to roll out via your MDM.
It continuously inventories every IDE extension, browser extension, skill, MCP server, and package-manager install (Homebrew, npm, PyPI) — name, publisher, version, permissions, hash. Metadata only; source never leaves the device.
We correlate each plugin against our threat intel and return a verdict. The agent enforces your allowlist — block, quarantine, or warn — before risky plugins run.
Fleet inventory, allowlist decisions, and detections across IDEs, browsers, and AI agents — for the whole org.
Understands skills and MCP servers as first-class assets — not an afterthought bolted onto an endpoint agent.
IDE, browser, and AI-agent plugins in a single inventory and a single allowlist.
We correlate every plugin SBOM against our own analysis and leading feeds. You get the verdict — never the burden of running intel.
The allowlist is enforced on the endpoint. Risky plugins are blocked or quarantined before they execute.
Metadata and SBOM only. Source code and intel never leave their respective sides.
RBAC, SIEM integration, and an audit trail on every allow/deny decision.
Device managers see your OS apps. Browser consoles see one browser. We see every plugin — IDE, browser, AI agent, and package manager — across the whole fleet, with verdicts and enforcement.
| Capability | JamfApple MDM | Chrome EnterpriseBrowser mgmt | KoiNow Palo Alto | PluginSecPlugin AIDR |
|---|---|---|---|---|
| Browser-extension control | ◐policy lists | ✓ | ✓ | ✓ |
| Edge, Firefox & Safari too | ◐ | –Chrome only | ✓ | ✓ |
| IDE extensions (VS Code, JetBrains, Cursor) | – | – | ✓ | ✓ |
| AI-agent skills & MCP servers | – | – | ✓ | ✓ |
| Package managers (Homebrew, npm, PyPI, Cargo, RubyGems, Go) | – | – | ✓ | ✓ |
| Dedicated plugin threat intel & verdicts | – | ◐3rd-party | ✓ | ✓ |
| Endpoint allowlist enforcement | ◐MDM, not plugin-level | – | ✓ | ✓ |
| Cross-platform endpoints (Win / Mac / Linux) | –Apple only | ✓ | ✓ | ✓ |
| Independent — no ecosystem lock-in | ◐ | ◐ | –Palo Alto | ✓ |
Jamf and Chrome Enterprise are adjacent categories — device and browser management — that each cover only part of the plugin surface. Koi is the closest peer and was acquired by Palo Alto Networks in 2026; PluginSec stays independent and vendor-neutral. ✓ full · ◐ partial · – none
PluginSec is enterprise-only and onboarded by invitation. Tell us about your team and we'll set up a demo on your fleet.