New capabilities bring discovery, access control, and runtime protection to agents, MCP servers, and skills running on employees' devices.
New York, September 28, 2026 / PRNewswire / — Enterprise AI and the Agent Security Platform Noma today announced the expansion of terminal agent security capabilities on the Noma platform. Terminals have become one of the biggest blind spots in enterprise AI security; as agents, MCP servers, and skills are already running on employees' laptops and possess the same permissions and credentials as the employees who installed them. The new capabilities of Noma can detect agents, MCP servers, and skills running on employees' devices, implement access control over the operations they are allowed to perform, and utilize and Response (including AI-DR and AI for detection and response) to prevent dangerous behaviors at runtime. Now, policies and context can be transferred between each agent across SaaS, custom-developed, and terminal environments, enabling security teams to manage the entire agent asset base through a single control plane.
Developers use coding agents such as Claude Code, Cursor, Codex, and Windsurf to process source code and production infrastructure. Business users rely on productivity agents like Claude Cowork to handle documents, browsers, SaaS applications, and internal data. MCP servers and skills extend this capability to databases, code repositories, and other systems as well. Agents can chain these operations within a single session without requiring manual approval for each step, and this access mechanism has been in place long before any potential attackers could intervene.
This type of risk does not require the exploitation of vulnerabilities. According to Noma, a recent security researcher discovered that the Grok Build coding assistant of xAI uploads the entire tracked code repository along with its complete Git history to the provider's cloud, even when it has been explicitly instructed not to open any files. Simply approving an agent is not sufficient. Security teams need a method to detect these new agents as they appear and to implement policies when they perform operations. Noma states that their shared Runtime Context Engine integrates identity, permissions, policies, and behavior into a unified signal.
Discovery and Governance
Terminal activities leave local evidence in configuration files, skill directories, connector history records, and running processes. Noma utilizes existing EDR or MDM systems to convert this evidence into real-time listings of agents on managed devices, MCP servers, skills, and associated accounts. Noma continuously assesses the risks associated with these assets, including the presence of keys in agent instructions, unsandboxed executions, and excessive proxy capabilities, among others.
This list will be directly connected to Noma Access Control, transforming the intelligents and tools that already exist on employees' devices into governable assets. Access Control integrates three capabilities:
- Governed Registry— Each agent, MCP server, and skill will be assigned a clear status: Approved, Pending Review, or Blocked; newly discovered assets will automatically be added to the registry.
- Identity - Aware Policy– Noma assigns each agent to its corresponding human user, and links this identity with the users and groups of the identity provider (IdP). As a result, policies can be implemented on a per-user, per-group, per-tool, or across-the-organization basis.
- Tool - and Action - Level ControlPolicies can override agents, MCP servers, skills, individual tools, and specific actions; therefore, read permissions can remain widely open, while creation, update, or deletion operations are limited to a smaller group of users.
Runtime protection is provided through AI-DR.
AI-DR serves as the runtime threat protection layer for Noma. It monitors the skills actually used by the agent, as well as the MCP servers and tools, establishing a baseline for the agent's behavior. It detects attempts at prompt injection, sensitive data leaks, malicious intentions, tool poisoning, out-of-bound operations, and instances where the agent deviates from its intended or established behavior. Noma indicates that this protection can be extended across entire sessions, correlating prompts, tool calls, tool responses, data access, identities, and behaviors over a period of time. This enables Noma to identify threats that gradually emerge through a series of originally permitted actions. Each detector can be independently adjusted to perform monitoring, alerting, guidance, blocking, inline shielding of sensitive data, or to defer certain operations to manual processing. The protection must continue even as the agent moves away from the laptop, as an approved database or API tool could potentially turn a routine task into a large-scale deletion operation.
"Agents on terminals possess some of the highest levels of authorization within the company, yet security teams often fail to notice them before issues arise," said Niv Braun, CEO and co-founder of Noma Security. "Extending our access control and AI-DR models to terminals means that security teams can gain the same visibility and enforcement capabilities that they already have in SaaS and our proprietary agent environments, right where these agents are expanding most rapidly."
Noma indicates that Noma Open Enforcement can apply these strategies to the existing enterprise architecture, including agent hooks, AI and MCP gateways, SDK, as well as EDR and MDM. These strategies will override those of Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity, and OpenClaw agents. The company states that enterprises can start deploying with hundreds of AI-DR strategies and protection configurations optimized for different industries and agent types, which reflect their collaboration experience with dozens of Fortune 500 security teams. Noma also plans to introduce Agent Boundaries at the endpoint to impose business boundaries on agent behavior defined by the enterprise.
For more information on how Noma protects agents in the terminal, please visit: https :// noma.security / platform / endpoint-agents.
About Noma
Noma indicates that the company is a specialist in creating AI and intelligent agent security platforms for enterprises. Noma can detect behavioral threats, govern the operations allowed to be performed by intelligent agents, and protect AI in various environments where these agents operate: including self-developed applications built on AWS Bedrock, Azure AI Foundry, and Databricks; SaaS intelligent agent platforms such as Microsoft Copilot Studio and Salesforce AgentForce; as well as pre-built intelligent agents like Claude Code, Cursor, and GitHub Copilot running on developers' devices. Noma states that the company has received support from Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures, and SVCI, and its solutions have been widely adopted by Fortune 500 companies. It has also been recognized by Gartner as a leader in the fields of AI, trust, risk, and, security, and management ( AI TRiSM ).
Media Contact
ICR for Noma
[ email protected ]











