Security Boulevard
Follow
The Half of Agent Security You’re Not Governing
The governance of AI agents faces a fundamental asymmetry: while MCP servers provide structured logs, the "Skills" that drive agent reasoning remain forensic black holes. As high-risk capabilities—such as arbitrary code execution and state changes—become prevalent in nearly 60% of enterprise deployments, traditional models like the "Rule of Two" are failing to prevent autonomous destruction. To counter this, Noma Security proposes the No Excessive CAP framework, focusing on the three controllable levers of defense: Capabilities, Autonomy, and Permissions.