# Knostic

**Canonical:** https://apis.io/providers/knostic/  
**Website:** https://www.knostic.ai/  
**APIs profiled:** 1

Knostic secures the AI agent supply chain inside the enterprise. Its platform discovers shadow AI, coding assistants, MCP servers and IDE extensions in use across an organization, then scans them for prompt injection, data exfiltration, secret and PII leakage, and destructive commands. Knostic runs AgentMesh, a public reputation and threat-intelligence service that continuously discovers, tracks and scans AI agent skills, Model Context Protocol servers, and VS Code / IDE marketplace extensions — roughly 80,500 skills, 4,800 MCP servers and 59,900 extensions as of July 2026 — and exposes that catalog with per-version scan verdicts through a REST API whose read endpoints answer anonymous callers. Knostic also ships a substantial open-source portfolio: AgentSonar (shadow-AI network detection), OpenAnt (LLM-based vulnerability discovery), MCP-Scanner, and security and telemetry plugins for OpenClaw agents.

## Kin Score — 48.4 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (-0.6 from 49.0).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 62.6 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 60.5 |
| Developer Ergonomics | 40.5 |
| Commercial Clarity | 43.4 |
| Access Clarity | 43.4 |

## Agent readiness — 34.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (4)

- **Knostic extensions API** — VS Code / IDE marketplace extensions with risk assessment
- **Knostic mcp API** — Model Context Protocol servers discovered and scanned by AgentMesh
- **Knostic scans API** — On-demand security scans and scan history (API key required)
- **Knostic skills API** — AI agent skills (SKILL.md) discovered and scanned by AgentMesh

## MCP servers (1)

- **Knostic MCP Server**

## Agentic access (1)

- **Knostic Agentic Access** — 12 operations · 2 acting · 1 human-in-the-loop

## Security (3)

- **Knostic Authentication** — http · 1 scheme
- **Knostic Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Knostic Trust Center** — SOC 2 Type 2

## Tags

Company, Security, Artificial Intelligence, AI Agents, Agent Security, Supply Chain Security, MCP, Threat Intelligence, Developer Tools, Shadow AI

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/knostic/). Scores are computed from the provider's own public artifacts under a published rubric.
