Your AI Agent Already Talks to the Internet. Who Checks What It Touches?
This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Executive Summary
AI coding agents and copilots are no longer autocomplete. They fetch pages, clone repositories, call MCP tools, and run shell commands as part of ordinary engineering work. That means developer environments now open outbound connections at machine speed, often to destinations no security review ever named.
Most organizations still treat agent risk as a prompt-policy or model-governance problem. The gap is operational. The agent is an execution path. If that path can reach staged attacker infrastructure (domains, IPs, poisoned code repos) during MITRE ATT&CK Resource Development (TA0042), your Mean Time to Preempt (MTTP) collapses inside the IDE, not only inside the SOC.
TrustGate is Malanta's answer for that path: a free, open-source set of Cursor enterprise hooks that inspect where an agent is about to send bytes, check those destinations against a reputation provider (Malanta Pre-Attack Intelligence by default), run a behavioral pass for known attack shapes, and return a verdict before the action runs. Leadership gets a controllable policy mode (from educate-first warn to fail-closed enforce). Security and platform teams get an audit trail. Developers keep working without a second product to learn.
If your organization is adopting AI agents, the question is no longer whether agents will contact the outside world. They already do. The question is whether Pre-Attack Intelligence sits on that path.
Most security leaders did not plan for the IDE to become an outbound threat surface.
Yet that is what AI coding agents changed. Ask an agent to "pull the latest package," "clone that repo," "fetch the docs," or "call the MCP tool," and you have authorized a machine to contact infrastructure on your behalf. The human still owns the intent. The agent owns the bytes.
What rarely gets the same scrutiny as model selection or data-loss policies is the destination layer: the domains, IP addresses, and GitHub repositories the agent is about to touch. Those destinations are exactly where adversaries stage work during Resource Development, before classic Indicators of Compromise (IOCs) exist.
In this blog, we look at why that gap matters for any organization adopting agents and copilots, and how TrustGate puts Indicators of Pre-Attack (IoPAs) on the developer execution path without asking teams to rip out their stack.
Agents expanded the setup window into day-to-day engineering
Attackers do not begin at payload delivery. They register domains, stand up hosts, publish or compromise repositories, and wire delivery paths while defenders still see quiet time. That setup window is MITRE ATT&CK TA0042. Pre-Attack Prevention exists because those signals are observable and actionable earlier than post-compromise IOCs.
AI agents compress how fast a developer can reach that infrastructure. An agent does not wait for a browser bookmark or a change ticket. It parses a prompt, extracts a URL or owner/repo, and acts.
Industry data already shows how AI reshapes Resource Development itself. Anthropic's June 2026 research found that three of the five highest-risk AI techniques sit in Pre-Attack Resource Development, with 69% of AI-enabled actors using AI for Develop Capabilities (T1587) and 57.9% acquiring infrastructure (T1583). When both sides use AI, timing becomes the control.
The issue for defenders is simple: if security only watches email gateways, web proxies, and the SOC, it misses the agent loop where a single approved session can open many outbound contacts.
What most AI-security programs miss
Prompt filters, approved-model lists, and sandbox policies matter. They do not answer the question TrustGate was built for:
Is the external domain, IP, or GitHub repository this agent is about to contact something we should allow right now?
That is a reputation and policy question, not a creativity question. It is also a pre-attack question. A repository can look like ordinary open source while carrying a malicious identity. A domain can sit in staging long before malware hashes appear in a feed. If the agent can reach it first, your organization just volunteered to be early traffic.
Security teams already struggle to operationalize threat intelligence at human tempo. Malanta's Feed Economy survey (2025) found 84% of organizations still rely on manual or reactive TI processes, and 0% measure pre-attack disruption. Agents do not wait for that triage queue. They need a check at the moment of action.
TrustGate: Pre-Attack Intelligence on the agent path
TrustGate is a set of Cursor enterprise hooks, published by Malanta as a free open-source project under the MIT License. Before an agent action runs, the matching hook extracts candidate destinations, asks a reputation provider whether to block, runs a behavioral Agent Threat Rules (ATR) pass over the content, and returns a verdict.
It covers the surfaces where agents actually move bytes:

Malanta is the default, officially supported reputation provider, including domain, IP, and code-repository checks. Teams that need another vendor can point TrustGate at a generic REST reputation API with no code changes. The plugin stays local-first: raw commands, file contents, and prompts are not transmitted. Only extracted indicators leave the machine for the reputation lookup (plus an opt-in audit sink if you configure one).
That design matters for security-minded personas who live in Cursor every day. TrustGate is not a slide about AI risk. It is a control that fires in the workflow where agents already operate.
Policy modes that match how organizations actually adopt agents
Day-one hard blocks are how security tools get uninstalled. TrustGate ships with that reality in mind.
- warn (default): A flagged destination is blocked once with an explanation. Re-running the same action proceeds. Educate first, without pretending risk does not exist.
- ask: On supported Cursor versions, flagged shell and MCP actions pause for a native human approve/reject decision.
- enforce: Fail-closed posture for fleets that are ready. Flagged destinations, and provider or configuration failures that would otherwise leave you blind, deny the action.
- report-only / off: Observe or disable without removing the install path.
Admins can scope workspaces, lock managed keys via MDM-style env files, enable time-boxed overrides when policy allows, and export decision logs for review. Developers get a decision_id and a clear reason instead of a silent fail.
For technical staff, the operating model is deliberately boring: install, set an API key, restart Cursor, then use trustgate doctor and trustgate explain when a verdict needs context. The agent also receives a bundled skill so it reads the verdict correctly. An allow is not proof a host is clean. It is a policy outcome under the active mode.
Why this is thought leadership, not a feature drop
Organizations adopting AI agents are writing a new control plane whether they admit it or not. The old split (security owns the perimeter, developers own the IDE) breaks when the IDE becomes an autonomous client.
Pre-Attack Prevention belongs there for the same reason it belongs left of the SOC: Resource Development infrastructure is visible before delivery. Putting IoPAs on shell, MCP, fetch, and repo actions shortens MTTP where modern engineering actually happens.
TrustGate is how Malanta makes that argument concrete and open. Inspect the packaging on the Cursor Directory. Read the code, architecture, and admin model in the Malanta-TrustGate repository. Fork it. Point it at Malanta or at your own provider. Contribute ATR rules. Treat agent outbound access as a first-class security surface.
The Bottom Line
AI agents did not invent Resource Development. They made it reachable from everyday development work at a speed humans cannot manually supervise. If your AI program has model policy but no destination control, you have a readiness gap sitting inside the tool your engineers trust most.
TrustGate closes that gap with open hooks, Pre-Attack Intelligence by default, and policy modes that scale from individual adoption to fleet enforce.
Install TrustGate, connect your Malanta API key, and put Pre-Attack Intelligence on the agent path before your next agent session does it for you. Start at the Cursor plugin page or the open-source repo.








