Classification: public-surface
You shipped AI agents fast. Watch makes sure they can't be turned against you - and hands you the report your customers' security team is about to ask for.
OWASP Agentic Top 10 // NIST IR 8596 // MCP security
Security grade
High-severity findings on the public surface. Immediate attention advised.
- HIGHTool description carries injected instructionsAAI · TOOL-POISONING
- HIGHUnauthenticated MCP server enumerableAAI · PRIVILEGE-COMPROMISE
- MEDShell-exec tool exposed without scope guardAAI · TOOL-MISUSE
The three reasons companies come to Watch.
Deal Unblock
Unblock your deal
Enterprise procurement teams are adding AI security reviews to their vendor questionnaires. Watch hands you the assessment report they're about to ask for - before they ask.
Pass the security review holding up your deal. Get the report their security team is about to demand.
Compliance
SOC2 / EU AI Act / Audit
Demonstrate control over your AI agents for SOC2 Type II, EU AI Act obligations, and audit prep. Documented evidence of security posture - not checkbox compliance.
Evidence for SOC2 / EU AI Act / audit prep.
Find It First
Find it before they do
Prompt injection, tool abuse, data exfiltration, privilege escalation - the OWASP Agentic Top 10 maps exactly what attackers look for in AI systems. Watch looks first.
Find how your agent can be turned against you before someone else does.
Standards mapping
Findings mapped to OWASP Agentic Top 10 and NIST IR 8596
Every finding in every Watch report is mapped to the frameworks your customers’ security teams already use. You get a document that speaks their language before they even ask.
See what’s exposed before an attacker does.
Paste a public MCP server URL. The scanner passively reads your public surface — tool schemas, exposed capabilities, anything visible without authentication — and grades what it finds.
- +Passive observation only — no scanning or exploitation.
- +No account or authorization required.
- +Findings mapped to OWASP Agentic Top 10 + NIST IR 8596.
// example output
verdict
Several medium and high-severity findings on the public surface.
findings
- [HIGH] Prompt injection via tool description fieldAAI · TOOL-POISONING · NIST IR 8596 §4.2
- [MED] Excessive tool permissions — filesystem scope too broadAAI · TOOL-MISUSE · NIST IR 8596 §5.1
- [LOW] Tool schema discloses internal service namesAAI · SENSITIVE-DISCLOSURE · NIST IR 8596 §4.5
› 12 tools enumerated · 2 accept user-controlled input reaching system prompts
Three tiers, one engagement at a time.
- 01Free
Snapshot
Passive, public-surface observation of your MCP server or agent endpoint. No scanning, no exploitation, no signed authorization required. A quick read of what's exposed before we go deeper.
Passive, public-surface only. No scanning or exploitation without signed authorization.
- 02
Assessment
A signed, authorized engagement that goes below the surface. Tool abuse paths, prompt injection vectors, data exfiltration risks, and OWASP Agentic Top 10 coverage - mapped and remediated.
Requires signed authorization. Report maps every finding to OWASP Agentic Top 10 and NIST IR 8596.
- 03
Watch
Ongoing watch over your agent's attack surface. New tool registrations, schema changes, configuration drift, and emerging OWASP Agentic findings - all surfaced before they become incidents.
Subscription. Alerts on posture changes. Quarterly posture report.
Know what's exposed before an attacker does.
Request a Watch assessment and we'll scope it to your AI systems. Not ready for a full engagement? The free Snapshot gives you an immediate read on your public surface.
Tell us what you run.
A short note is enough to start. We’ll reply to scope the assessment to your AI systems and confirm what’s in scope before any work begins.
OWASP Agentic Top 10 · NIST IR 8596 · Signed report