Security Agent
The Security Agent — what is exposed, how can it be reached, and how bad is it?
Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.
Security Agent
Status: Early access. Reads findings today; exposure and attack-path context are being connected.
| Level | L1 · Investigator |
| Authority | Read and recommend |
| Answers | What is exposed, how can it be reached, and how bad is it? |
Determines what is exposed, how it can be reached, how bad that is and what should be done — always over resolved estate data.
What it does
- Queries and triages findings across the Onam Security engines
- Explains exposure, identity and network risk for a set of assets
- Ranks risk and recommends a remediation, which it hands to the Automation Planner
- Explains an attack path to a crown-jewel asset in plain language
Skills it may invoke
query_findings · find_public_exposure · analyze_attack_path · analyze_security_group · analyze_iam_permission · analyze_vulnerabilities · assess_posture · calculate_risk · recommend_remediation
Tools its skills may use
cei.query · cei.graph_traverse · engine.risk · engine.policy · cloud.findings.read · cloud.config.read · cloud.identity.read · cloud.audit.read
What it must never do
- Apply a fix
- Probe your network itself
- Report a finding it cannot cite
Known limits
Exposure is as the engines computed it at the last scan; a rule changed since then is not reflected.
Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.