Install
Install oktsec
AI agents execute shell commands, write files, and call APIs on your machine. You have no visibility into what they do. oktsec intercepts every tool call and scans it before execution.
$ brew install oktsec/tap/oktsecRunning in 3 steps
brew install oktsec/tap/oktsecoktsec runOne command. Auto-discovers all MCP clients, generates config, creates Ed25519 keypairs, wraps MCP servers, connects Claude Code via hooks.
http://127.0.0.1:8080/dashboardUse the access code shown in your terminal.
After oktsec run
First scan happens automatically when you use any AI tool. Events appear in real time.
What happens once it's running
Know exactly what your agents did
Every Read, Write, Bash, and API call captured with full context. Before and after execution. Filter by agent, tool, or verdict.
Catch prompt injection before it executes
217 rules across 16 categories. Context-aware scanning drops false positives below 1%. No LLM required.
Prove to your CISO that agents are monitored
SHA-256 hash chain with Ed25519 signatures. Immutable audit trail. SARIF export for compliance workflows.
Understand a 2-hour session in 30 seconds
AI-powered session analysis: risk level, what happened, what to do. Human vs agent interaction timeline.
What oktsec finds on your machine
Auto-discovers and connects. No configuration needed.
Start with observe. Enforce when ready.
Observe
Logs everything, blocks nothing. See what your agents do before changing anything.
oktsec runEnforce
Blocks threats before execution. 217 rules, sub-millisecond verdict.
oktsec run --enforceOr toggle from the dashboard at any time.