Agent execution control

Before an agent gets a consequential tool, the call is bounded, confirmable, stoppable, and provable.

Authority at the tool call. Then evidence. Deny the wrong call before it runs — not a threat-intel dashboard.

Not SOC 2 certified. No pen-test letter. No named customers. SARIF is the artifact you can take to GitHub Advanced Security.

RWA Readiness Clinic Validate private-credit structures before tokenization.

Buyer clinic

Field lanes — need, obstacle, gap, path

Same thesis on every lane: before a consequential tool runs, the call must be bounded, confirmable, stoppable, and provable. Pick your field; each card names what you actually need, what breaks today, and where to start on Shield. Full specialized clinic — eight lanes with symptoms, anti-patterns, and 10-step paths.

RWA · private credit

RWA Readiness Clinic

Need
Validate loan structure, SPV lifecycle, custody, and regulatory dependencies before tokenization.
On platform
File v3 evidence slots, run nine clinical gates, get GO / CONDITIONAL / NO_GO with blockers.

MCP · IDE agent platform

Cursor / Claude / custom MCP hosts

Need
Deny credential reads and out-of-scope tools before JSON-RPC executes — with a reason the developer sees in the IDE.
Obstacle
Allowlists are menus: they do not block a novel tool name or a resources/read on .env until after exfiltration.
Gap
No inline PDP, no STEP_UP for sensitive writes, no signed receipt tied to the blocked call.
On platform
  1. Run DENY demo — expect DENY on hostile .env read.
  2. Install: npx @noetfield/shield-cursor init --yes then shield-cursor prove.
  3. Pick agent id + pack on MCP install form; copy bridge command; restart IDE.
  4. Verify: POST /v1/adapter/mcp/proxy or IDE “Verify Shield” on the MCP page.
Artifacts
DENY receipt in bridge output · policy pack from GET /v1/shield/policy-packs

Agent supply chain · AppSec

Skills, plugins, trojanized MCP configs

Need
Static scan of natural-language instructions plus trace-driven boundary eval before marketplace skills ship.
Obstacle
npm audit and SCA miss prose instructions (“ignore prior rules”, hidden shell steps) and MCP server JSON that never hits a package registry.
Gap
No unified scorecard that merges artifact findings with hostile trace regression in one ALLOW / DENY / STEP_UP gate.
On platform
  1. Agent Guard → paste skill or mcp.json → Analyze artifact.
  2. Boundary eval tab → policy from GET /v1/boundary-eval/policies → run trace JSON.
  3. Scorecard → POST /v1/agent-security/scorecard for unified gate verdict.
  4. Enable share on scan → download SARIF from exports.sarif.
Artifacts
Report JSON · SARIF · GET /v1/reports/{id}/brief.md

CISO · GRC · vendor risk

Audit packets without certification theater

Need
Framework tags on findings, SARIF for GitHub Advanced Security, and an executive brief — without implying SOC 2 Type II or a pen-test letter.
Obstacle
Vendor decks claim “SOC 2 mapping” that reads like certification; GHAS has no agent-tool-call findings unless you export SARIF yourself.
Gap
No honest posture line, no tamper-evident receipt verify, no org assessment that merges URL + agent + boundary in one gate.
On platform
  1. Org assessment form — URL + consent (+ optional artifact).
  2. Or homepage org form with the same required fields.
  3. Pull GET /v1/reports/{id}/sarif and /brief.md from shared report.
  4. CI: scan with share:true → GHA SARIF upload.
Artifacts
SARIF 2.1.0 · CEF · executive brief · framework tags (mapping, not certification)

Platform ops · SRE · release

Deploy and release gates

Need
Post-deploy URL scan plus optional boundary eval on release artifacts — pass, warn, or fail with a shareable report ID.
Obstacle
CI only checks containers and dependencies; live MCP endpoints, session cookies, and agent hooks drift after promote.
Gap
No unified hooks/release that ties surface scan to agent policy without bolting three vendors together.
On platform
  1. After deploy: POST /v1/hooks/deploy with url + consent:true.
  2. Release: POST /v1/hooks/release — use hook tester first.
  3. Fail pipeline when gate is fail; store report_id on ticket.
  4. Guide: /deploy-gate/ · deploy-security-gate.
Artifacts
Hook JSON verdict · shareable report · SARIF when share enabled

Threat intel · IR

Agent supply chain campaigns

Need
Curated 2026 agent/MCP incidents, IOC hunt across artifacts, and control-plane checklist for identity blast radius.
Obstacle
Generic CVE feeds do not cover trojanized skills, MCP secret leaks, or OAuth consent phishing against coding agents.
Gap
No single surface that links incident context to live hunt and checklist without a SIEM project.
On platform
  1. Threat Intel → GET /v1/threat-feed.
  2. IOC Hunt → paste text → POST /v1/ioc-hunt.
  3. Control Plane → checklist + POST /v1/control-plane.
  4. Export CEF from shared reports for SIEM tickets.
Artifacts
Threat stories · IOC matches · control-plane posture report

Identity · IAM · control plane

Agent inventory and blast radius

Need
Register agents, simulate hostile traces, enforce CI gate on policy packs — before production MCP servers multiply.
Obstacle
IAM tools track humans and service accounts, not per-repo Cursor agents with rotating MCP tool lists.
Gap
No control-plane checklist that scores OAuth, session fixation, and MCP exposure on the deployed app URL.
On platform
  1. POST /v1/agent-control/agents register agent metadata.
  2. GET /v1/shield/policy-packs · GET /v1/agent-control/packs.
  3. POST /v1/agent-control/simulate/{scenario} hostile regression.
  4. Control plane tab → optional Entra/Intune/MCP paste → assess URL.
Artifacts
Agent registry receipt · simulation outcome · checklist gaps

Engineering management · Team lead

Team coverage without blocking delivery

Need
One screen: repos protected, blocked actions this week, pending STEP_UP — understandable in 30 seconds.
Obstacle
Security asks for agent governance; teams hear stop using Cursor. No coverage % across the monorepo.
Gap
No team summary API, no dogfood sweep, no two-minute prove ritual to show value.
On platform
  1. Team summary — GET /v1/shield/team-summary.
  2. Run npm run dogfood:sweep for coverage by repo.
  3. Pilot squad: npx @noetfield/shield-cursor init --yes + prove.
  4. Required check: GHA gate on main.
Artifacts
Coverage % · weekly DENY count · policy pack per environment

Regulated · banking · healthcare · fintech

PHI, PCI, and production guardrails

Need
Production Guard pack, STEP_UP on prod touches, signed receipts, no shadow MCP on regulated workstations.
Obstacle
Developers use agents on machines that reach prod VPN; examiners ask for AI access logs and get IDE screenshots.
Gap
No proof DENY fired before upstream on credential paths; no Docker sidecar when cloud PDP is restricted.
On platform
  1. Init with Production Guard on MCP page.
  2. Prove hostile .env read before exam season.
  3. Register agents with environment=production on control plane.
  4. Examiner packet: org assessment + honest scope line.
Artifacts
Signed receipts · SARIF to GRC · quarterly hostile sim archive

Operations playbook

Every kit, form, and API — ready on this platform

Complete vendor questionnaires and internal readiness from live surfaces — not PDFs to request later. Full operations kit — every form field, API body, and error fix. ABCP money controls and diligence ZIP live on banking.noetfield.com.

Kit / formWhereRequirements to completeOutput
URL surface scanURL Scan tab · POST /v1/scanApp URL · consent · optional share:trueReport id · SARIF when shared
Agent artifact scanAgent Guard · POST /v1/agent-scanArtifact type · paste contentFindings + CWE tags
Boundary evalAgent Guard → Boundary · POST /v1/boundary-evalPolicy or authority JSON · trace eventsALLOW/DENY/STEP_UP + receipt
Org assessment/org-assessment/ · POST /v1/org-assessmentURL · consent · optional artifactUnified gate · SARIF · brief
MCP / CursorMCP pageAgent id · pack · bridge install · verifyRuntime DENY + receipt
Deploy / release hooksHook testerLive URL · consent:true · optional boundary policypass / warn / fail
SARIF → GHASSARIF guideShare scan · download SARIF · upload actionGitHub code scanning alert
OpenAPI/v1/openapi.jsonNone — full API catalogVendor API diligence
Money readiness gatebanking.noetfield.com/gateSix radio questions (honest answers)Signed GO / CONDITIONAL / NO-GO
Policy demo walkcontrol.noetfield.com/sandboxSix in-page demo stepsReceipts sandbox:true
Vendor diligence ZIPvendor/pack.zipDownload · map to questionnaireCSV · OpenAPI · schemas
Vendor request lanes/requestPick lane · email opens with required fieldsWalk · NDA · pilot SOW path
Full buyer clinic/buyer-clinic/Pick lane · follow 10-step path per roleSymptoms · anti-patterns · module map

Agent supply chain guard

Static artifact analysis plus trace-driven boundary evaluation. Artifact scan matches IOCs and trojanized patterns. Boundary eval runs six deterministic suites on normalized traces from sandboxed adapters. Policy decision point returns ALLOW, DENY, or STEP_UP per action.

Artifact scan

  • Trojanized skills.sh IOCs (1.7M install campaign)
  • Remote loader + TLS-disable patterns
  • Credential harvest instructions
  • System prompt hijack attempts
  • Risky MCP server URLs

Boundary eval suites

  • Loading suites from API…

Evaluator does not execute untrusted agents. Adapters submit traces from Docker/VM sandboxes.

CI integration

Deploy gate after every publish

POST your live URL after deploy. Returns pass, warn, or fail plus a shareable report.

curl -sS -X POST "https://scan.noetfield.com/v1/hooks/deploy" \
  -H "content-type: application/json" \
  -d '{"url":"https://your-app.com","consent":true}'
curl -sS -X POST "https://scan.noetfield.com/v1/hooks/release" \
  -H "content-type: application/json" \
  -d '{"url":"https://your-app.com","consent":true,"policy_id":"skills-marketplace-untrusted-v1","subject":"release-gate","events":[{"type":"tool_call","name":"shell"}],"policy":{"fail_on":["critical","high"]}}'

Try hooks in browser

For security & GRC teams

Audit-ready posture, not just a grade

Reports can tag findings with OWASP, CWE, and CIS references. That is mapping on a report, not a SOC 2 certification. Export SARIF into GitHub Advanced Security. Pull an executive brief. Track drift between deploys.

Control plane

POST /v1/agent-control/decide — ALLOW / DENY / STEP_UP per action. POST /v1/agent-control/simulate/* for hostile regression.

Policy packs

GET /v1/boundary-eval/policies — Cursor, MCP, CI, skills marketplace, support bot.

Agent approval

POST /v1/agent-security/scorecard — static + boundary in one denied/conditional/approved gate.

Receipt verify

POST /v1/boundary-eval/verify — audit SHA-256 receipts for tamper evidence.

SIEM export

GET /v1/reports/{id}/cef — Splunk, Sentinel, Chronicle compatible CEF.

Unified release gate

POST /v1/hooks/release — URL scan + optional boundary eval with webhook and export URLs.

Org assessment

POST /v1/org-assessment now includes boundary traces in unified posture.

curl -sS -X POST "https://scan.noetfield.com/v1/hooks/boundary" \
  -H "content-type: application/json" \
  -d '{"policy_id":"skills-marketplace-untrusted-v1","subject":"skill-pr","events":[{"type":"tool_call","name":"shell"}]}'

Run org assessment

One POST merges URL scan, optional agent artifact, and boundary trace into a unified gate.

Platform API

REST + MCP for agents and CI

Every module is available over HTTP. Agents call MCP at /api/mcp. CI hooks use deploy gate at /v1/hooks/deploy.

POST /v1/scan

Live URL surface scan

POST /v1/agent-scan

Agent artifact static analysis

POST /v1/agent-control/decide

Policy decision point (ALLOW/DENY/STEP_UP)

POST /v1/agent-control/simulate/{scenario}

Hostile trace regression

GET /v1/agent-control/packs

Evaluation packs (enterprise-baseline, mcp-core)

POST /v1/boundary-eval

Trace boundary eval + SHA-256 receipt

GET /v1/boundary-eval/policies

Enterprise authority policy packs

POST /v1/agent-security/scorecard

Unified agent approval gate

POST /v1/hooks/boundary

CI boundary gate

GET /v1/threat-feed

Curated threat stories

POST /v1/ioc-hunt

IOC matching

POST /v1/control-plane

Posture assessment

POST /v1/org-assessment

Unified org posture brief

GET /v1/reports/{id}/sarif

SARIF for GHAS / DevSecOps

GET /v1/reports/{id}/brief.md

Executive markdown brief

POST /api/mcp

MCP JSON-RPC tools

GET /v1/platform

Platform metadata

GET /v1/openapi.json

OpenAPI 3.1 catalog

POST /v1/hooks/deploy

CI deploy gate

curl -sS https://scan.noetfield.com/v1/platform | jq .
curl -sS -X POST https://scan.noetfield.com/v1/agent-scan \
  -H "content-type: application/json" \
  -d '{"content":"…skill text…","artifact_type":"skill"}'

FAQ

Platform questions

Is this a SIEM or EDR?
No. Shield is a deterministic security platform focused on surface scans, agent supply chain, threat context, and control-plane checklists. It complements your existing stack.
Where does threat intel come from?
Curated from The Hacker News Threat Intelligence expert insights, plus Zenity, CERT Polska, Sygnia, and PortSwigger disclosures. Updated as major 2026 campaigns land.
Does Agent Guard replace npm audit?
No. Agent Guard targets natural-language skill instructions and MCP configs that static package scanners cannot read.
Can agents use this via MCP?
Yes. Tools: scan_url, scan_agent_artifact, hunt_iocs, assess_control_plane, get_threat_feed, evaluate_boundary_trace, shield_decide, shield_evaluate, get_report, run_agent_scorecard, agent_control_decide, simulate_hostile_agent, list_boundary_policies, run_org_assessment, verify_receipt, get_ci_gate, register_agent, list_eval_packs. See OpenAPI.
Does Shield export SARIF for GitHub Advanced Security?
Yes. Shared reports include GET /v1/reports/{id}/sarif in SARIF 2.1.0 with CWE and severity on every finding.
Is Shield SOC 2 certified?
No. Shield is not SOC 2 certified, does not sell a pen-test letter, and does not list named customers. Reports can tag findings with OWASP, CWE, and CIS references. That is mapping, not a certification. SARIF export is the artifact you can upload to GitHub Advanced Security.