
Akto Atlas Now Discovers Every AI Plugin Across Your Workforce
Akto Atlas discovers every plugin running across Claude, Codex, and GitHub Copilot, showing the endpoints it's installed on, which marketplace it came from, and the risk it introduces.

Krishanu
AI agents are no longer fixed products. Employees can change what they know, what they can access, and what they can do with a single plugin install.
A developer can add a code-review workflow to Claude Code. A business user can turn Cowork into a role-specific assistant. Another employee can connect ChatGPT, Codex, or GitHub Copilot to new tools and internal systems.
Most of this happens without security knowing.
Today, we are introducing workforce-wide AI plugin discovery in Akto Atlas. Atlas now surfaces every plugin running across Claude, ChatGPT, and GitHub Copilot, shows where it runs, how many endpoints use it, which marketplace it came from, and whether it introduces risk.
Plugins Are Amplifying AI Supply Chain Risk
An AI plugin is a packaged extension that adds new capabilities to an agent. It can combine skills, commands, agents, hooks, connectors, scripts, and MCP servers in a single install.

That install can teach an agent a new workflow, connect it to an external system, inspect prompts, react to tool calls, or run code at specific points in the agent's lifecycle.
Plugins are already available across Claude Code, Cowork, ChatGPT, Codex, and GitHub Copilot. While the packaging differs between platforms, the pattern is the same: employees can extend an approved AI agent in minutes, often at the user or project level.
Security may have approved the agent. It has not necessarily approved everything installed inside it.
Marketplaces Make Plugins Easy to Install, and Hard to Track
Plugin marketplaces make extensions easy to discover, install, share, and update. They can be official directories, community catalogs, company-managed marketplaces, Git repositories, or local sources.
That convenience creates a new software supply chain inside enterprise AI tools.
Each plugin brings its own publisher, code, instructions, dependencies, update path, and access. A plugin from an approved internal marketplace has a different trust profile from one pulled from an unfamiliar public repository. Even a legitimate plugin can introduce risk through the way it reads files, passes context to the model, invokes tools, or changes over time.
Marketplace provenance therefore matters as much as the plugin name. Security needs to know not only what was installed, but where it came from and how far it has spread.
Hookify Shows How Trusted Plugins Can Introduce Risk
Hookify is distributed through Anthropic's official Claude Code marketplace. The plugin helps users create rules that warn about or block unwanted behavior, such as dangerous commands or edits to sensitive files.
Researchers found that Hookify read rule files from a project's .claude directory and passed their contents into Claude through the hook system's trusted context. An attacker who placed a malicious rule file inside a repository could use that path to steer the model after a developer opened and trusted the project.
The researchers tested five malicious instructions disguised as normal project conventions against Claude Opus 4.6. Claude followed all five, exposing environment variables and local-only secrets. None were flagged as prompt injection.
The point is not that Hookify was designed to be malicious. It was built to prevent unwanted behavior. The finding shows how a useful plugin can still create a trusted path from repository content into an agent's decisions.
It also shows why an official marketplace listing is not the end of the security review. Teams still need to know which endpoints have the plugin, which agent is loading it, and whether its behavior creates risk in their environment.
What Akto Atlas Now Shows You
Akto Atlas brings plugins into the same security inventory as the AI agents using them.
For every plugin, Atlas shows:
Agent: Identify whether it is running in Claude, ChatGPT, Codex, GitHub Copilot, or another supported AI surface.
Marketplace: Trace the plugin back to the source from which it was installed.
Risk: Flag plugins that require investigation before they expose data or influence unsafe agent behavior.
Endpoint count: See whether the plugin exists on one machine or has spread across the workforce.

This gives security the context that an isolated file, process, or agent admin console cannot provide on its own.
You do not just see that a plugin exists. You see where it sits in the organization and how urgently it needs attention.
From Shadow Plugins to Governed AI Adoption
Plugins are making AI agents more useful, and employees will continue installing them. The answer is not to slow down every workflow with a manual approval process. It is to make plugin adoption visible enough to govern.
With Akto Atlas, security teams can:
Discover plugins employees never reported
Map every plugin to the agent and endpoints using it
Verify its marketplace source
Identify unapproved or risky installations
Prioritize remediation based on exposure
Employees keep the flexibility to extend their AI tools. Security gets the visibility to catch risky plugins before they become widespread incidents.
Experience enterprise-grade Agentic Security solution

