← TrendWatcher
Dev.to
5/10

AgentTrustee Monitor

An enterprise dashboard that inventories every AI agent identity in your org (what repos it can read, what channels it can publish to) and flags any combination that creates the "lethal trifecta" (private read + untrusted input + public write) before an attacker does.

Target user

CISOs and security leads at companies running GitHub Agentic Workflows, Copilot agents, or custom AI bots with standing credentials

Features
  • Continuous discovery of agent identities across GitHub, Slack, email, and CI systems
  • Lethal-trifecta risk scoring per agent with specific remediation steps (narrow scope, separate read vs write identities)
  • Drift alerts when an agent's token scope expands without an approval ticket
  • Compliance reports tying agent permissions to SOC 2, ISO 27001, and internal AI-use policies
Why now

The GitLost disclosure proved prompt-injection-to-exfiltration works against GitHub's own agent platform, and most organizations granted broad scopes to AI agents without auditing them.

Signals · overall 5/10
Demand
7/10

GitLost disclosure was widely covered across security press; CSA Q2 2026 report found 89% of deployed AI agents fail baseline security, indicating strong enterprise pain.GitLost: How We Tricked GitHub's AI Agent into Leaking Private ReposThe AI Agent Lethal Trifecta - Lab Space

Whitespace
3/10

Noma Security launched 'Agentic Access Control' in June 2026 doing exactly this: continuous automatic inventory of every AI agent/MCP server with owner, permissions, connected tools — a direct incumbent.Noma Launches Agentic Access Control to Govern AI Agents and MCP Servers Across the EnterpriseAgentic Access Control Platform | Noma Security

Monetization
6/10

Enterprise agent security platforms attract VC-backed pricing; Noma is well-funded and the category is selling into CISO budgets, but competition and market nascence limit near-term ARR capture for a new entrant.Noma Launches Agentic Access Control to Govern AI Agents and MCP Servers Across the Enterprise

Longevity
7/10

The lethal trifecta is a structural property of any tool-using LLM with mixed trust boundaries, so the problem persists as long as agents exist; Simon Willison's framing and CSA research suggest multi-year relevance.The lethal trifecta for AI agents

Feasibility
4/10

Requires deep read integrations across GitHub, Copilot, Slack/Teams, cloud IAM and custom agents; permission metadata is fragmented and many agent runtimes lack mature audit APIs, making a comprehensive inventory non-trivial.Agentic Access Control Platform | Noma Security

If Your AI Agent Has Write Access to Public Repos, Audit It Now — Here's Why · 21 reactionsDev.to · 2026-07-28 (today)