Every agent. Every MCP server. Nothing started.
Whoever can change the files a coding agent reads can steer it. Cordon reads every one of them, for every agent in use, from the repository to the laptop to the CI runner, without starting an agent or a server.
Claude
Cursor
GitHub Copilot
Windsurf
Gemini
OpenAI
JetBrains
VS Code
MCP
Five kinds of file decide what an agent does.
Each one committed to the repository, each one a way in. Cordon reads all five for every agent below, in every dialect, and a probe of each location proves it.
Claude Code
Cursor
GitHub Copilot
Windsurf
Gemini CLI
OpenAI Codex
Kiro
Amazon Q
JetBrains Junie
Augment
Trae
Roo Code
Continue
Zed
goose
opencode
Cline
Twenty ways an agent turns on you.
The open catalogue of agent attacks, all of it that applies.
815 of the 825 rules, translated, screened for runaway patterns and graded by how often each fires on benign text. A rule that would warn on more than one of 1,263 real instruction files needs a second signal before it counts.
- Prompt injection
- Tool poisoning
- Context exfiltration
- Agent manipulation
- Privilege escalation
- Excessive autonomy
- Skill compromise
- Data poisoning
- Model abuse
- Model security
- case-insensitive
- NFKC-normalised
- invisible characters stripped
- confusable letters folded
- base64 decoded
| Test cases, each on its rule's scan path | Cases | Result |
|---|---|---|
| Attacks, each on its rule's scan path | 3,941 of 4,034 | 97.7% |
| Evasions, read offline for intent | 233 of 289 | 80.6% |
| Benign left clean (the catalogue's near-misses) | 4,038 of 4,369 | 92.4% |
For the wording no rule anticipated.
A language model reads the text an agent is handed: instruction files, skills, tool descriptions and hook commands, and nothing else. The text is fenced as data, and a verdict counts only when it quotes evidence that is really there, so a model talked round by what it read adds nothing.
Every rule still runs; the judge only adds. A malicious verdict warns, or fails the build with --judge-blocks. Verdicts are cached by model and text, so a rescan costs nothing, and a judge that cannot be reached marks the scan incomplete rather than passing it.
What a server tells the model, before it ever starts.
Local servers are resolved to their package and read from the registry tarball. Remote servers are asked for their tool list with --online, over https only, and every tool is fingerprinted. Approve a server once; a description it changes afterwards is a finding, because a server decides what it tells the model at request time.
- 01Readevery MCP config dialect and the exact launch command
- 02Resolvenpx -y pkg@version or uvx to the precise package
- 03Fetchthe tarball, verified against the registry digest, never installed
- 04Checkwhat each tool tells the model, and the server's own code
- 05Watchwhat a remote server serves now, against the tools you approved
Agent findings, beside the malware they enable.
claude-code-action on comments anyone can post, MCP servers fetched unpinned at start-up, characters a reviewer cannot see in CLAUDE.md: each one a finding with an owner and an SLA, from pull request to laptop.
The agents your people actually run.
The laptop agent reads a fixed list of agent and MCP config paths in each home directory, and reports the inventory and its findings to Cordon Cloud through your MDM. Never a file's contents, never a credential, and it prints exactly what it would send.
cordon-scanner agent inventory # what is configured herecordon-scanner agent report # send it, as disclosedcordon-scanner agent mcp-approve # record what remote servers serve now
Know what your AI is made of.
Every agent, skill, MCP server, rules file and model in each repository, with where it is and whether it is pinned, as a CycloneDX 1.6 AI bill of materials.