Agentic Posture Visibility
Agentic Posture Visibility for Cursor, Claude Desktop, Claude Code, Codex, and OpenClaw
See the structure before any AI verdict — deterministic, entirely without an LLM. EDAMAME's Agents tab surfaces the whole agent fleet: Exposure — every AI agent on the machine, approved or not, with the MCP servers and tools it binds, what it can reach, its blast radius, and a structural Flight Recorder of everything it touched, over a 30-second “AI work safety” fleet-health read; a Self-Augmentation Score — how well the humans directing these agents augment themselves; and a Path of Enlightenment that turns that score into a guided way to improve. Every observation rolls up to EDAMAME Hub as a posture check, per device — no new console. Security that accelerates humans.


Why visibility
Visibility first: deterministic, zero-config.
Most teams cannot answer basic questions about the AI agents already on their machines: which agents are installed, which MCP servers and tools they bind, what they can reach, what they have touched, and how well the humans directing them augment themselves. EDAMAME answers these structurally — Exposure (every agent and its blast radius, over an “AI work safety” fleet-health read), a Self-Augmentation Score, and a guided Path of Enlightenment — on day one, with zero configuration, including agents nobody installed a plugin into. When you then need a verdict on behavior, Agentic Security adds divergence scoring and attack-pattern detection on top.
Exposure
Every AI agent on the machine, approved or not, with observed-coverage validation, the MCP servers and tools it binds, its reach and blast radius sorted by danger, harness coverage (AgentField, Rippletide), and a structural Flight Recorder of everything it touched — the former Inventory and Blast Radius, merged into one governed home for the whole fleet.
AI work safety
A 30-second fleet-health read across the whole exposure surface — estimated spend, active vs discovered agents, sessions in error, repeated-failure clusters, and the deterministic token-waste rate, with a ranked agent list and an alert feed of recent findings.
Path of Enlightenment
The default landing: a per-workspace journey from Awakening to Enlightened, driven by the Self-Augmentation Score and capped by attributed gates — security findings, blast radius, divergence, a paused observer — with a Best next step to raise it.
Self-Augmentation Score
A 0–100 score with a six-axis quality radar — utilization, diversity, leverage, efficiency, trend, and craft — plus a Coverage data-confidence badge, used, dormant, and dead skills, and the per-workspace context tax: how well humans augment themselves with AI.
Fleet roll-up
Local observations. Fleet posture checks.
The visibility pass converts local observations into ordinary posture checks that ride the existing score and security-checks pipeline up to EDAMAME Hub: agents running without a governance harness, unconfined agents with a dangerous blast radius, and discovered agents whose observer is paused. Define policy on these checks and enforce zero trust from EDAMAME Hub — for example, only authorize agents wrapped in a governance harness such as AgentField or Rippletide to connect to your IdP and providers.
See the structure on every host
EDAMAME Security runs the structural pass on the developer workstation; EDAMAME Posture runs the same pass headless on CI/CD runners, servers, and self-hosted agent hosts such as OpenClaw.
• Agent inventory with observed-coverage validation
• MCP server and tool inventory per agent
• Blast radius, trust zones, and harness coverage
Roll up to EDAMAME Hub
Each observation lands in the views a CISO already uses: the device score, the Security Checks catalog, per-device failed checks, Security Score events, and Engagement escalations. Define policy on any of these checks and EDAMAME Hub's posture-gated conditional access enforces it as zero trust — only compliant hosts stay on your IdP and provider allow-lists.
• Agents present but no governance harness
• Unconfined agents with a host amplifier
• Discovered agents with a paused observer
Every code-and-pipeline endpoint
Visibility across workstations, runners, and agent hosts
Agentic Posture Visibility is not workstation-only. The same structural pass covers developer workstations, CI/CD runners, isolated VMs, and self-hosted agent hosts — so the exposure, reach, blast-radius, and augmentation questions get the same evidence-backed answer on every machine that touches your code.
Developer workstations
EDAMAME Security inventories Cursor, Claude Desktop, Claude Code, and Codex on the developer machine — agents, MCP servers, tools, reach, and its blast radius.
Runners and agent hosts
EDAMAME Posture runs the same structural pass headless on CI/CD runners, isolated VMs, and self-hosted OpenClaw servers — the unattended half of the agentic pipeline.
OWASP GenAI scorecard
An OWASP GenAI Top 10 scorecard graded from the structural facts the visibility pass collects — evidence-backed answers.
From visibility to security
When you need a verdict, add Agentic Security
Visibility shows the structure; Agentic Security judges behavior. The divergence engine compares declared intent with observed system behavior, attack-pattern detection watches the same telemetry for credential harvest and token exfiltration, and a critical finding can pull a host from your IdP and provider allow-lists through EDAMAME Hub.
Intent divergence
Compare what the agent says it is doing with what the machine actually does — processes, files, network, posture — and score the divergence on an evidence trail.
Attack-pattern findings
The same host telemetry detects credential harvest, token exfiltration, and sensitive-file access — the patterns behind the axios npm RAT, tj-actions, and litellm attacks.
Automatic isolation
Once an attack pattern or a divergence verdict is detected, EDAMAME Hub conditional access automatically isolates the compromised agent host from your IdP and provider allow-lists.

