EDAMAME Posture

Secure CI/CD runners and any server running AI agents

Use EDAMAME Posture to harden CI/CD runners and any server running AI agents, cloud or self-hosted. Each host is observed independently from outside the agent, and findings carry OWASP GenAI plus scoped MITRE ATLAS evidence. Where the Netskope device identity is available through the helper or an elevated posture process, a critical finding can remove that host’s device tag and let the customer’s Real-time Policy deny access.

Two lanes

One control surface for runners and agent servers, cloud or self-hosted

Stop suspicious egress and fail builds when behavior violates allowlisted destinations. EDAMAME Posture turns supply-chain response from post-mortem into measurable runtime evidence across CI/CD runners and any server running AI agents, cloud or self-hosted — catching the attack patterns that reach CI through the package chain, such as the axios npm RAT, the tj-actions/changed-files GitHub Actions compromise, and the litellm PyPI takeover.

Runners and build hosts

Run posture checks before secrets, builds, and deploys. Keep Linux, macOS, and Windows runners aligned with the policy you expect.

Policy gates and posture proof

Turn host trust into automated gates for repository access, secrets access, and build approvals without inventing a separate security workflow.

Self-hosted agent hosts

Use the same EDAMAME Posture foundation to harden OpenClaw and Hermes servers and isolated VMs, then observe each agent independently from outside — at the host boundary — layering runtime verification and attack-pattern findings for defense in depth.

Features

Harden the host. Layer runtime detection on top.

Measure pipelines failed due to network policy violations. Track mean time to detect anomalous egress, credential harvest, token exfiltration, and tool poisoning during CI jobs. Lane A is CI/CD posture hardening for runners and build hosts. Lane B is the servers running AI agents, cloud or self-hosted, with runtime evidence and attack-pattern findings.

Ultra Easy Deployment

Simplify your code-and-pipeline integration with our Ultra Easy Deployment.

Automated Hardening
Pipeline Threat Model
GitHub Actions workflow step using the EDAMAME Posture action
EDAMAME Posture CI log: remediated threats and the security score after remediation
GitHub Actions job log with the EDAMAME Posture session dump and allowlisted destinations
Ultra Easy Deployment

Simplify your code-and-pipeline integration with our Ultra Easy Deployment.

Automated Hardening
Pipeline Threat Model
GitHub Actions workflow step using the EDAMAME Posture action
EDAMAME Posture CI log: remediated threats and the security score after remediation
GitHub Actions job log with the EDAMAME Posture session dump and allowlisted destinations
Ultra Easy Deployment

Simplify your code-and-pipeline integration with our Ultra Easy Deployment.

Automated Hardening
Pipeline Threat Model
GitHub Actions workflow step using the EDAMAME Posture action
EDAMAME Posture CI log: remediated threats and the security score after remediation
GitHub Actions job log with the EDAMAME Posture session dump and allowlisted destinations

Install EDAMAME Posture on runners and servers

Use the CLI on macOS, Windows, and Linux to harden CI/CD infrastructure, protect the servers running AI agents, cloud or self-hosted, and connect runtime verification plus attack-pattern findings where they matter.

EDAMAME Posture GitHub Action configuration snippet

Install EDAMAME Posture on runners and servers

Use the CLI on macOS, Windows, and Linux to harden CI/CD infrastructure, protect the servers running AI agents, cloud or self-hosted, and connect runtime verification plus attack-pattern findings where they matter.

EDAMAME Posture GitHub Action configuration snippet