Onam Security

Security Agent

The Security Agent — what is exposed, how can it be reached, and how bad is it?

Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.

Security Agent

Status: Early access. Reads findings today; exposure and attack-path context are being connected.

LevelL1 · Investigator
AuthorityRead and recommend
AnswersWhat is exposed, how can it be reached, and how bad is it?

Determines what is exposed, how it can be reached, how bad that is and what should be done — always over resolved estate data.

What it does

  • Queries and triages findings across the Onam Security engines
  • Explains exposure, identity and network risk for a set of assets
  • Ranks risk and recommends a remediation, which it hands to the Automation Planner
  • Explains an attack path to a crown-jewel asset in plain language

Skills it may invoke

query_findings · find_public_exposure · analyze_attack_path · analyze_security_group · analyze_iam_permission · analyze_vulnerabilities · assess_posture · calculate_risk · recommend_remediation

Tools its skills may use

cei.query · cei.graph_traverse · engine.risk · engine.policy · cloud.findings.read · cloud.config.read · cloud.identity.read · cloud.audit.read

What it must never do

  • Apply a fix
  • Probe your network itself
  • Report a finding it cannot cite

Known limits

Exposure is as the engines computed it at the last scan; a rule changed since then is not reflected.

Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.