Indexes your environment
OpenLatch builds a live graph of your agents' MCP servers, skills, rules, and plugins — refreshed at the start of every session.
60-second setup. Every major AI agent. Detection powered by the open-source cybersecurity community.
Free forever for 1 agent Apache 2.0 client SOC 2 in progress
Plugged into every major AI agent
OpenLatch builds a live graph of your agents' MCP servers, skills, rules, and plugins — refreshed at the start of every session.
Each event is analyzed and dispatched to the best-fit security tool from the OpenLatch Library, automatically.
Risky actions are blocked, warned, or logged — before your agent executes them.
OpenLatch routes every AI agent action to the community-driven security tool best equipped to handle it. Zero touch. Full coverage.
The threat landscape moves fast. OpenLatch connects detection built by the cybersecurity community directly to your agent — so you stay ahead without picking vendors.
Connect every major AI agent to every security tool through a single interface — with enterprise-grade primitives: real-time detection, multi-channel alerting, reporting, and audit.
Your agent is stopped before it runs a malicious skill, calls a hostile tool, or executes a destructive command. Nothing harmful reaches your system.
Zero-touch doesn't mean zero control. Configure routing, alerting, and enforcement to match the most demanding enterprise requirements.
Paste this into Claude Code, Codex CLI, OpenClaw — your agent handles the rest.
Works on macOS, Linux, and Windows. Node.js 18+ required.
Sign up and onboard your first agent from your browser.
From prompt injection to skill poisoning to multi-step exploitation — OpenLatch covers the full AI agent threat surface.
A skill or MCP server quietly ships malicious instructions that hijack your agent at runtime.
ClawHavoc (Mar 2026) — a poisoned MCP skill exfiltrated SSH keys from OpenClaw users at scale.
Learn moreUntrusted content — a web page, a file, an email — hijacks your agent's instructions mid-task.
Learn moreYour agent pastes an API key, password, or PII into a log, request, or commit.
Learn moreA hallucinated rm -rf runs against the wrong directory — before you can react.
Learn moreYour agent installs a poisoned npm, PyPI, or crate dependency that runs at install time.
Learn moreSeveral benign-looking actions chain into an exfiltration or privilege escalation. The danger isn't any single step — it's the composition.
Learn moreOpenLatch isn't yet another security tool. It's the platform that unifies the best detection from researchers, vendors, and the open-source community behind a single API — so AI agents are protected by the entire industry, not one company.
by OpenLatch
by OpenLatch
by OpenLatch
by OpenLatch
by OpenLatch
by Endor Labs
by OpenLatch
by OpenLatch
by OpenLatch
by OpenLatch
by OpenLatch
by Endor Labs
by Semgrep
by Snyk
by Noma Security
by 1Password
by MintMCP
by Oasis Security
by Semgrep
by Snyk
by Noma Security
by 1Password
by MintMCP
by Oasis Security
Install counts are illustrative for v1.