# Optimus Labs > Optimus Labs is the agentic AI security platform for the enterprise endpoint. We discover, govern, and secure every AI agent, MCP server, and skill running on the endpoint, from installation to runtime, scored against the OWASP Top 10 for Agentic Applications. ## What Optimus Labs does Optimus Labs gives security, engineering, and IT teams visibility and control over the AI agents already running on enterprise endpoints. Coding agents, desktop assistants, autonomous agents, MCP servers, and custom skills can read sensitive data, call external tools, and take instructions from untrusted sources. When one agent holds all three — untrusted input, sensitive data access, and external action — it forms the Lethal Trifecta. Optimus enforces the Agents Rule of Two so no single agent ever combines all three properties. ## Key definitions - **Lethal Trifecta**: When an AI agent simultaneously has untrusted input, sensitive data access, and external action capability. This is the precondition for prompt-injection data exfiltration and unauthorized action. - **Agents Rule of Two**: A security framework that prevents any agent from holding all three Trifecta properties at once. - **Agent Asset Inventory**: Discovery and governance of every agent, MCP server, and skill across the endpoint fleet, including shadow AI. - **Agent Posture Management**: Static analysis of an agent's configuration, permissions, tools, and prompts, mapped to the OWASP Top 10 for Agentic Applications. - **Agent Behavior Anomaly Detection**: Runtime monitoring of every agent action with alert, block, and justify options. - **Owner management**: Organization of inventory, detections, findings, and policies by Owner. ## Who it is for - CISOs and security teams responsible for AI agent risk - Engineering and platform teams running AI agents in production - CIOs and IT leaders responsible for enterprise-wide AI governance ## Core capabilities - **Map**: Discover every agent, MCP server, and skill across the organization, including shadow AI. - **Inspect**: Actionable security findings with evidence, mapped to OWASP Top 10 for Agentic Applications. - **Defend**: Enforce policies, block risky actions, and maintain audit trails at scale. - **Own**: Organize inventory, detections, findings, and policies by Owner. ## How it fits the security stack - **EDR** sees processes on endpoints. - **SASE / CASB** sees SaaS traffic on the network. - **DLP** sees files. - **Optimus** sees agent intent, tool calls, and data paths at the agent layer that EDR, SASE, and DLP cannot see. ## Deployment and data A lightweight endpoint agent deploys through existing MDM. Inventory and posture findings land in minutes. No code changes, no proxy in front of the model, no workflow friction. Enforcement starts in observe-only mode. Only metadata needed for inventory, posture, and detections leaves the endpoint; it is encrypted in transit, scoped per tenant, retained for 90 days, and never used to train models. ## Open source Optimus Labs releases focused research tools as open source. leakpatrol is a forensic CLI that checks whether a Coder deployment was exposed to the Coder registry infrastructure hijack (see https://www.optimuslabs.io/leakpatrol/). grokpatrol is a forensic CLI for investigating the Grok Build CLI codebase-upload exposure (see https://www.optimuslabs.io/grokpatrol/). ## Pages - [Home](https://www.optimuslabs.io/): The Lethal Trifecta, the Agents Rule of Two, and how Optimus secures agents on the endpoint. - [Book a demo](https://www.optimuslabs.io/book-demo): A 30-minute walkthrough — map your agents, score their posture, and see runtime enforcement on a live endpoint. - [Security](https://www.optimuslabs.io/security): How Optimus serves security teams — discovery, posture, and runtime detection. - [Engineering](https://www.optimuslabs.io/engineering): How Optimus serves engineering and platform teams. - [Enterprise](https://www.optimuslabs.io/enterprise): Enterprise-wide governance, owners, and audit. - [Civilizations threat briefings](https://www.optimuslabs.io/research/briefings): First-party AI incident research from Civilizations, the Optimus Labs threat research team. Each briefing traces an attack chain inside or affecting the agent layer, with sources, indicators, and remediation. - [Briefings corpus (Markdown)](https://www.optimuslabs.io/research/briefings.md): Full text of every briefing in one Markdown file, best for LLM ingestion. - [Briefings corpus (JSON)](https://www.optimuslabs.io/research/briefings.json): Structured briefing data: severity, categories, vendors, indicators, timeline, sources, remediation. - [Briefings index (Markdown)](https://www.optimuslabs.io/research/briefings/index.md): Titles, dates, severities, and canonical URLs. - [Briefings RSS](https://www.optimuslabs.io/research/feed.xml): New briefings feed. - [Briefings llms.txt](https://www.optimuslabs.io/llms-briefings.txt): Per-briefing Markdown and JSON endpoints. - [grokpatrol](https://www.optimuslabs.io/grokpatrol/): Open-source forensic CLI for the Grok Build CLI codebase-upload exposure, built by Optimus Labs. - [leakpatrol](https://www.optimuslabs.io/leakpatrol/): Open-source forensic CLI that checks a Coder deployment for exposure to the Coder registry infrastructure hijack, built by Optimus Labs. - [Subscribe](https://www.optimuslabs.io/subscribe): Get new Civilizations threat briefings by email. ## Optional - [GitHub](https://github.com/optimuslabs-io): Open-source projects and security research. - [Substack](https://futureofcyber.substack.com/): Essays and research on the future of cyber. ## Company - Legal name: Optimus AI, Inc. - Brand: Optimus Labs - Founded: 2025 - Founders: security engineers from Carnegie Mellon, Devo, and NCC Group - Website: https://www.optimuslabs.io - Contact: hello@optimuslabs.io ## Threat intelligence exports (Civilizations briefings) - STIX 2.1 bundle, all briefings: https://www.optimuslabs.io/research/briefings.stix.json - IOC CSV, all briefings: https://www.optimuslabs.io/research/briefings-iocs.csv - Per briefing: /research/briefings/.stix.json, .misp.json, .ioc.txt, .ioc.csv - Research index for LLMs: https://www.optimuslabs.io/llms-briefings.txt