The Infrastructure Land Grab
Between September 28 and October 7, the market for agent runtime safety shifted from a theoretical concern to an infrastructure priority. NVIDIA, Atlassian, Cloudflare, Backslash Security, and ClawSecure all shipped or embedded new safety mechanisms. This sudden activity is not a coincidence; it is a scramble to control the layer that sits beneath the Model Context Protocol (MCP), Agent-to-Agent (A2A) communication, and the Policy Administration Point (PAP) protocol stack.
The deeper issue is that while these vendors are all building “safety,” they are solving for entirely different problems. We are seeing a divergence in architecture: some focus on sandboxing, others on identity, authorization, or observability. There is currently no consensus on what a runtime safety layer must contain, leaving enterprises to navigate an incoherent foundation of incompatible security stacks.
The Four Pillars of Runtime Safety
To understand the current landscape, we must look at the four functions this layer is intended to serve: sandboxing (containing agent actions), identity (distinguishing agent actors), authorization (defining permissions), and observability (tracking execution). No single vendor is currently solving for all four.
NVIDIA’s OpenShell (Sep 28) focuses on the kernel-level sandbox, using hardware-backed watchdogs on BlueField-4 DPUs to quarantine rogue agents. It is a classic containment play. In contrast, Atlassian’s AMP (Oct 7) prioritizes Non-Human Identity (NHI), treating agents as first-class citizens with distinct profiles and owners, effectively bringing agents into the same visibility framework as human employees.
Cloudflare (Oct 7) is taking a broader, systems-level approach with its agentic security harness. By integrating Dynamic Workers for sandboxed execution and Durable Objects for state management, they are attempting to bridge the gap between execution and state. Meanwhile, Backslash Security and ClawSecure are focused on the vulnerabilities inherent in the MCP specification itself, highlighting that the “safety” problem is often a protocol-level issue rather than a model-level one.
The Endpoint Blind Spot
What matters here is the shift in where these attacks occur. Backslash Security’s recent analysis of the 2026 MCP spec reveals a critical structural vulnerability: three major attack surfaces — stateless portable handles, deprecated root scopes, and MCP Apps (SEP-1865) — exist entirely on the endpoint. These threats live inside the developer’s machine, the IDE, and local MCP servers.
Because these vectors never touch the network, traditional network gateways are effectively blind. This renders perimeter-based security obsolete for agentic workflows. If your security strategy relies on monitoring traffic at the network edge, you are missing the entire execution environment where agents actually operate.
Connecting the Protocol Stack
This fragmentation is occurring against a backdrop of rapid protocol development. We have already seen the industry move toward standardizing agent state management, the PAP protocol stack, and MCP testing infrastructure. The runtime safety layer is the substrate that must support all of these.
ClawSecure’s recent findings regarding auto-fetch vulnerabilities in Notion and Linear underscore the urgency. Their research showed that 17 out of 20 obfuscation techniques successfully bypassed the safety filters of 14 different models. When the models themselves cannot consistently block threats, the runtime layer becomes the only line of defense.
Builder Implications
For infrastructure decision-makers, the current reality is a “defense in depth” strategy that is actually just a collection of incompatible, ad-hoc integrations. Without a standardized runtime safety layer, every agent deployment requires custom plumbing to ensure that actions are allowed, observable, and containable.
The vendor that standardizes this layer first will control a significant moat. Just as MCP became the standard for tool integration and A2A is standardizing agent communication, the runtime safety layer is the next battleground for infrastructure dominance. Builders should prioritize modularity, assuming that the current “safety” tools will likely be replaced by a more unified, protocol-native standard in the coming year.
Verification Note: The research regarding ClawSecure’s findings on MCP vulnerabilities and the failure of various models to block obfuscated threats is based on independent testing and is covered in Post 131353. Vendor-specific claims regarding the efficacy of their respective safety harnesses are based on their own product documentation and primary announcements. No independent third-party replication of vendor-specific safety benchmarks has been published at the time of reporting.
