The Data Behind the Agent Governance Gap

The State of Agent Security 2026

414 unsanctioned AI tools per 1,000 employees. Four in five with no IT oversight. Half of all agent tools can run shell commands on the host. This report covers the numbers behind the shift from application risk to identity risk.
Download the complete report
"The unit of risk moved from the application to the identity eighteen months ago. Most security programs are still measuring the application."
Ofer Klein
Co-Founder & CEO

Executive Summary

414
unsanctioned AI tools per 1,000 employees at small and mid-size firms, even where 79% of SaaS is authorized
4 in 5
AI tools operating with no IT oversight, the share where agents actually live
50%
of 500 published agent tools can execute shell commands on the host machine
525
vulnerabilities disclosed across agent and LLM tooling in the last 18 months, at least 111 rated critical

Spotlight: The Toxic Combination

62% of the 500 agent tools examined can read local data and reach the internet in a single package: the exfiltration bridge. Two in five hold the full set, command execution, file access, and network egress, together. The person who installed the tool approved one power. Nobody approved the pair, and that's the combination a prompt-injection payload chains into a complete attack with no malware and no stolen password.

Spotlight: One Framework, 135,000 Stars, One Bad Webpage

OpenClaw passed 135,000 GitHub stars within weeks of release. It runs shell commands, manages files, and reaches corporate Slack, calendars, and drives through ordinary OAuth consent. Then researchers found its control interface could be hijacked from a single malicious webpage, even when bound to localhost. Its skill marketplace ran 12% malicious. An adjacent breach leaked 1.5 million agent tokens from a service running 770,000 agents. Adoption at that speed leaves no room to threat-model first.

Our Research Methodology

500
published MCP servers analyzed for shell access, file access, and network egress
260+
AI agents and applications covered in Reco platform telemetry
637
agent and LLM-tooling CVEs tracked against the public vulnerability record (NVD) since January 2025
3 sources
Reco platform telemetry, independent analysis of published npm MCP servers, and the public CVE record
Ready to See Your Own Agent Layer?

Get Ahead of the Agent Governance Gap

Your agents are already running. Do you know what they're doing?

Request a demo