Agentic Posture Visibility
See every AI agent — and how well your humans use them
Cursor, Claude Desktop, Claude Code, Codex, OpenClaw, and Hermes are already on your machines. EDAMAME shows the fleet from outside the agent — who is running, what they can reach, and a Self-Augmentation Score with a clear path to get better. Automatic. Zero install into the agent. Every observation rolls up to EDAMAME Hub. Security that accelerates humans.


Why visibility
Day-one answers. Zero config. Nothing to install into the agent.
Most teams still cannot answer the basics: which AI agents are running, what they can reach, and how efficiently humans use them. EDAMAME answers that on day one — Exposure, a Self-Augmentation Score, and a Path of Enlightenment — automatically from outside the agent. When you need a verdict on behavior, Agentic Security adds divergence scoring and attack-pattern detection.
Exposure
See every AI agent on the machine — approved or not — what it can reach, its blast radius, and a structural record of what it touched. One fleet-health read tells you if AI work is safe right now.
AI work safety
In thirty seconds: are agents healthy, wasting tokens, stuck in failures, or drifting? A ranked list and alert feed so humans know what to fix first.
Path of Enlightenment
A guided journey from Awakening to Enlightened — driven by how well you augment yourself with AI, with one clear next step when security or blast-radius gates hold you back.
Self-Augmentation Score
A score humans can raise: how effectively they use skills and tools, where context tax piles up, and which skills are used, dormant, or dead.
Fleet roll-up
From one host to fleet policy.
What EDAMAME sees on each host becomes ordinary posture checks in EDAMAME Hub — agents without a governance harness, unconfined agents with a dangerous blast radius, paused observers. Define policy on these checks and enforce zero trust — for example, prefer hosts where agents run inside a detected governance harness such as nono or Anthropic srt before they connect to your IdP and providers.
Every host. Same structural truth.
EDAMAME Security runs the structural pass on the developer workstation; EDAMAME Posture runs the same pass headless on CI/CD runners, servers, and self-hosted agent hosts such as OpenClaw and Hermes.
• Agent inventory with observed-coverage validation
• MCP server and tool inventory per agent
• Blast radius, trust zones, and sandbox harness coverage
Policy you can enforce in Hub
Each observation lands where CISOs already work: device score, Security Checks, failed checks, Security Score events, and Engagement escalations. Turn any of these into posture-gated conditional access — only compliant hosts stay on your IdP and provider allow-lists.
• Agents present but no governance harness
• Unconfined agents with a host amplifier
• Discovered agents with a paused observer
Every code-and-pipeline endpoint
One visibility story across workstations, runners, and agent hosts
Not just the developer laptop. The same visibility covers workstations, CI/CD runners, isolated VMs, and self-hosted agent hosts — so exposure, blast radius, and human-augmentation questions get the same evidence-backed answer on every machine that touches your code.
Developer workstations
See Cursor, Claude Desktop, Claude Code, Codex, and more on the laptop — every agent, its MCP reach, and its blast radius, before a plugin is ever installed.
Runners and agent hosts
The same structural pass, headless, on CI/CD runners, isolated VMs, and self-hosted OpenClaw or Hermes hosts — the unattended half of the agentic pipeline.
OWASP GenAI scorecard
Evidence-backed answers against the OWASP GenAI Top 10 — graded from the same structural facts the visibility pass already collects.
From visibility to security
Structure first. Verdict when you need it.
Visibility shows who is running and what they can reach. Agentic Security judges behavior — intent divergence, attack-pattern findings, and automatic isolation of compromised hosts through EDAMAME Hub.
Intent divergence
Compare what the agent says it is doing with what the machine actually does — processes, files, network, posture — and score the gap on an evidence trail.
Attack-pattern findings
Catch credential harvest, token exfiltration, and sensitive-file access — the patterns behind the axios npm RAT, tj-actions, and litellm attacks.
Automatic isolation
When a critical finding lands, EDAMAME Hub pulls the compromised host off your IdP and provider allow-lists — automatically.

