Integrations

Works with what you already run.

Every connection is read-only unless you ask for more, and each one changes what NoFly can tell you. This page explains what each one does, and lists only what ships.

What a connection does

Every connector does one of three jobs.

Jigsaw pieces cut from one chart, the last piece lowering into place
  • J1It adds a fact

    Something NoFly could not see alone: who owns an agent, whose bucket a command touched, whether a person still works here.

  • J2It supplies the denominator

    The “out of how many” behind every percentage. Without a fleet or network count, zero findings says nothing.

  • J3It opens a door outward

    A ticket, an approval in chat, an event in the SIEM, a pull request with the fix.

One command, four connectors deep

With nothing connected the gate still decides, it just decides with less, and says which questions it could not answer.

What you install

The pieces that put NoFly in the path.

Connectors tell NoFly what exists. These are the parts that sit between an agent and what it touches, so a decision can happen before the action does.

RoutingWhat goes through which gate
Coding agents on laptops
Hooks and MCP shim
Shell commands, tool calls, local MCP servers
Any MCP client
MCP gateway
Tool lists, calls and results
Apps calling models
Model proxy or gateway plugin
Prompts, completions, tool calls in model traffic
Agents you build
SDK
Prompts, tool calls, retrieved content, hand-offs
Developers in the editor
IDE extension
AI config files and model loads
People in the browser
Browser extension
Prompts sent to AI sites
  • P1Hooks inside coding agents

    Claude Code, Cursor, Windsurf, Gemini CLI, Codex CLI, Copilot CLI and Cline

    One command puts the gate inside each coding agent on a machine. Shell commands and tool calls are sent to it before they run, and the agent is told the decision and the reason.

    • Critical moves refused on the machine, even offline
    • Risky ones held for a person
    • A selftest proves each hook is really in the path
    • Prompts screened before they are sent, in Claude Code and Cursor
    npx @shomra/agent protect
    Open source · No account needed
  • P2MCP shim

    Local MCP servers in Claude Code, Cursor, Windsurf and Gemini CLI

    Wraps each local MCP server so it starts through NoFly. Tool calls are checked before they reach the server, and results are screened before the model sees them.

    • Poisoned or denied tools removed from the tool list
    • Runs fully local, or asks your policy when enrolled
    • One command to wrap, one to undo
    shomra mcp guard
    Open source · No account needed
  • P3MCP gateway

    Any MCP client: Claude Code, Cursor, Windsurf, VS Code and more

    Gives each agent one endpoint for every MCP server it is allowed to use. Tool lists, calls and results are screened in one place, and the agent signs in with its own credential.

    • Poisoned tool descriptions withheld and recorded
    • Server credentials kept by the gateway, never by the agent
    • Denied, revoked or quarantined servers refused
    Platform
  • P4Model proxy

    Apps and agents that call model providers directly

    A local proxy for nine model providers applies the same rules to model traffic with no code changes, and covers tools such as Aider that have no hooks.

    • Model calls screened for injection, secrets and personal data
    • Covers agents with no hook, such as Aider
    • Budgets that refuse the call over the limit
    Platform
  • P5Gateway plugins

    Kong, Envoy with Istio and Gloo, Traefik, LiteLLM, Portkey, Cloudflare Workers, Azure API Management and AWS API Gateway

    Adds NoFly to the API gateway you already run. Prompts and completions are screened and blocked there, and tool calls inside model traffic are withheld when policy says so.

    • APISIX and NGINX block prompts and record completions
    • An agentgateway plugin screens MCP tool calls and lists
    • Fail-closed available where you need it
    Customers
  • P6SDKs for the agents you build

    TypeScript and Python, with adapters for OpenAI, Anthropic, OpenAI Agents, MCP, LangGraph, LangChain, Vercel AI SDK, LlamaIndex, CrewAI, AutoGen, Semantic Kernel, Pydantic AI and Google ADK

    Puts the same gate inside your own code. Screen prompts and completions, check a tool call before it runs, screen tool results and retrieved documents, and verify hand-offs between agents.

    • guard(), checkToolCall(), screenToolResult() and handoff()
    • A tool call can be held for a person
    • Zero dependencies in either language
    • Runs you never instrumented joined in from Langfuse, Helicone or OpenTelemetry traces
    npm install @shomra/sdk · pip install shomra
    Customers
  • P7IDE extension

    VS Code and Cursor

    Checks AI config files as you open and save them, such as MCP configs, skills, CLAUDE.md, AGENTS.md and rules files, and shows each finding on the line that causes it.

    • Flags known-vulnerable models loaded in Python, notebooks and JavaScript
    • Gate status in the status bar
    • Explain a finding, or harden a model load, in one step
    No account needed
  • P8Browser extension

    Chrome, on ChatGPT, Claude, Gemini, Copilot and other AI sites

    Screens prompts before they leave the browser, shows which account is used on each AI site, and lists the extensions installed alongside it.

    • Observe, warn or enforce
    • Personal and company accounts told apart
    • Feeds shadow AI in Discover
    Customers

The CLI, hooks and MCP shim are open source under Apache-2.0 and run with no account. The SDKs, gateway plugins and browser extension are available to customers. Streamed completions are screened on LiteLLM and Portkey; on other gateways they pass unscreened.

Every connector

What each connection adds.

  • C1Identity providers

    A read-only app registration with directory permissions

    Your directory tells NoFly who people are, which non-human identities exist and which AI apps people granted access to. Service principals become agent identities, groups decide who may use an agent, and departed people are told apart from current ones.

    • Service principals seeded into the agent registry, monitored before they are enforced
    • AI apps people consented to with their work account, and the option to revoke them
    • Agents sign in without stored keys, using tokens from your identity provider or CI
    • SAML single sign-on and SCIM for your own team
    • Microsoft Entra ID
    • Okta
    • Google Workspace
    • OneLogin
    • Keycloak
    • Slack workspace
  • C2Endpoints and device management

    Read-only API credentials for your EDR and MDM

    Your EDR already records which programs run on every laptop. NoFly searches that telemetry for AI tools and configs, so it finds coding agents and MCP servers on machines it was never installed on. MDM gives the true size of the fleet, and can push the scan on a schedule.

    • AI found on machines without installing anything
    • The real number of machines behind every percentage
    • Scheduled scans rolled out through MDM
    • CrowdStrike Falcon
    • Microsoft Defender
    • SentinelOne
    • Intune
    • Jamf
    • Kandji
  • C3Network and proxies

    Log exports or API access from your secure web gateway

    Your proxy sees which AI services are reached and by whom. NoFly turns that into shadow AI by vendor and person, and checks whether the proxy’s own AI policy actually blocks or only watches.

    • Shadow AI by vendor, person and account type
    • The traffic denominator behind every count
    • Your proxy graded on the Control Ledger
    • Netskope
    • Zscaler
    • Chrome, Edge, Brave, Firefox
  • C4Hosted agent platforms

    An admin connection, plus callbacks where the platform supports them

    Agents built in business tools are imported by name as governed identities, starting in monitor mode so nothing breaks. Where the platform allows it, each tool call is sent to NoFly before it runs.

    • Every console-built agent in one registry
    • Inline blocking on Copilot Studio, Agentforce, Bedrock Agents, Azure AI Foundry and n8n
    • After-the-fact or log-based monitoring for the rest, labelled as such
    • Copilot Studio
    • Agentforce
    • Bedrock Agents
    • Azure AI Foundry
    • n8n
    • Microsoft 365 Copilot
    • Glean
    • Make
    • Gemini for Workspace
    • ServiceNow Now Assist
  • C5Cloud and AI providers

    Read-only keys or roles, never write access

    Model endpoints, deployed agents and AI keys land in the inventory with what each key can reach. When an agent runs a cloud command, NoFly can tell whether the account is yours, somebody else’s, or unknown.

    • Models, endpoints and keys with their real reach
    • Every cloud command an agent runs tied to an account
    • Served models and registries from your ML platforms
    • AWS
    • Google Cloud
    • Azure
    • OpenAI
    • Anthropic
    • Amazon Bedrock
    • Azure OpenAI
    • Hugging Face
    • Databricks
    • SageMaker
    • Vertex AI
    • MLflow
    • Snowflake
  • C6Secrets managers

    A read-only connection that lists secret names

    Knowing which values are real secrets lets NoFly follow them from where an agent read them to where it tried to send them. The credential broker can also hand agents short-lived access instead of long-lived keys.

    • Real secrets tracked as they move through a run
    • Short-lived, scoped credentials at the moment of use
    • Keys found on laptops matched to what they open
    • HashiCorp Vault
    • Azure Key Vault
    • Doppler
  • C7Code hosts and CI

    A GitHub App, a token, or the GitHub Action

    Repositories become a scan source for agent configs, skills, MCP servers and model files. A proposed fix becomes a pull request in one click, and the build gate refuses a dangerous change before it merges.

    • Risky AI config caught in the pull request
    • Fixes opened as pull requests and re-checked
    • Builds failed when an agent regresses under attack
    • GitHub
    • GitHub Actions
    • GitLab
    • Bitbucket
    • Gitea
    • Azure DevOps
    • Jenkins
    • CircleCI
  • C8Ticketing

    OAuth or an API token for your tracker

    A finding becomes a ticket with its evidence attached, and the ticket stays linked to the finding in both directions. Work is never routed to someone who has left.

    • Two-way sync between findings and tickets
    • Owners resolved from the inventory
    • Closed tickets re-checked before the finding closes
    • Jira
    • ServiceNow
    • Linear
    • Asana
    • Trello
    • ClickUp
    • monday.com
  • C9Chat, paging and SIEM

    A chat app, a webhook, or your SIEM’s collector

    Approvals and alerts go where people already are, and every decision ships to the system your security team already watches.

    • Approve or deny held actions from Slack or Teams
    • Pages for the things that cannot wait
    • Every event in Splunk, Datadog or Microsoft Sentinel
    • Slack
    • Microsoft Teams
    • Discord
    • PagerDuty
    • Splunk
    • Datadog
    • Microsoft Sentinel
    • Email and webhooks

Don’t see yours?

Most integrations take a read-only key and a few minutes. Tell us what you run and we will tell you honestly whether it is covered.

Book a demo
npm i -g @shomra/agent