Upwind Adds Real-Time Detection to AI Agent Security Lineup
New York, USA, July 30th, 2026, FinanceWire
Upwind Security, the runtime-powered cloud security company, has introduced two new capabilities aimed at protecting AI agents from the moment they are built to the moment they act in production. The company announced the Upwind AI Agent Context Scanner alongside the general availability of Upwind AI Detection & Response, known as AI DR.
The announcement reflects a shift in how AI agents operate inside organizations. What began as coding assistants running locally on employee machines has expanded into autonomous workflows operating across cloud environments. These agents do not simply respond to prompts. They call tools, invoke APIs, access data, and make decisions using real enterprise credentials.
What Shapes an Agent's Behavior
An agent's actions are not determined solely by its underlying model. They are shaped by a dynamic context built from skills, tools, Model Context Protocol connections, memory, and active instructions. Each of these components can inject content directly into an agent's reasoning process, which creates two distinct problems for security teams. First, organizations need a way to catch dangerous or ambiguous instructions before those instructions ever influence an agent. Second, they need to know when an agent's behavior shifts once it is running in production. Upwind's new offerings are built to address each side of that equation.
Scanning the Building Blocks of Agent Context
The AI Agent Context Scanner works by continuously analyzing the components that make up an agent's operational context. This includes skills that contain specialized prompts and workflow logic, tools that let an agent query databases, invoke APIs, or run scripts, and MCP connections that pull external data, memory, and instructions into the agent's execution environment.
Because any of these components can insert instructions straight into an agent's context window, a single malicious, vulnerable, or ambiguous instruction has the potential to redirect an agent's reasoning and misuse its permissions. The scanner is designed to catch this before it happens, evaluating these components wherever they run, whether on employee endpoints, in cloud infrastructure, or through managed AI providers. Findings are then enriched using context from the broader Upwind platform, so security teams can prioritize based on actual runtime risk rather than sorting through isolated alerts.
Detecting Agents That Have Gone Off Script
The second piece, AI DR, extends Upwind's existing runtime intelligence to agents already operating in production. It works by continuously baselining normal behavior for each agent, tracking which tools it calls, which APIs and data stores it touches, and what a typical session looks like.
When an agent's tool calls, destination endpoints, or session activity drift from that baseline, AI DR flags the change as it happens. Upwind then correlates that activity with workload identity, network topology, API traffic, data sensitivity, permissions, posture, and exposure. Instead of generating a bare alert, the system is built to tell security teams which agent was affected, what it did, what it touched, and why that activity matters. It can also reconstruct the path leading to the behavior, identify data that may have been exposed, and offer response guidance, including revoking a session or credential, reducing permissions, or reviewing downstream systems.
Moving Beyond a Static Inventory
Upwind frames this announcement as a step beyond simple AI inventory. Knowing which models, agents, tools, skills, and MCP connections exist within an organization remains a necessary starting point, since teams cannot secure what they do not know about. But an inventory alone only provides a snapshot in time. Two agents can look identical in a catalog while behaving in completely different ways once deployed. By pairing preventive context scanning with real-time detection and response, Upwind is positioning itself to give security and engineering teams a continuous view of the instructions shaping their AI agents and the actions those agents take.
Key Capabilities
The release covers discovery and analysis of AI agents, tools, skills, and MCP connections across endpoints, cloud infrastructure, and managed AI providers. It adds detailed inspection of the instructions entering an agent's operational context, ongoing behavioral baselining of agent sessions, tool calls, and destinations, and real-time detection enriched with signals spanning identity, data sensitivity, posture, permissions, and exposure. Security teams also get attack-path reconstruction, visibility into data impact, and guidance on remediation.
Contact
TVC AnalystEditorial@tvc.partners
Disclaimer. This is a paid press release.