August 13, 2026 5m read

Inside Cato’s Latest AI Security Innovations for Claude

Liron Hakim Bobrov
Liron Hakim Bobrov

Table of Contents

Wondering where to begin your SASE journey?

We've got you covered!
Listen to post:
πŸ”Š This audio player requires that "Preferences" cookies be accepted

Claude is moving quickly. Cato is innovating alongside it. With inference hooks, skills posture, and seamless deployment, teams can adopt new AI capabilities with security controls that are ready from day one.

Claude’s rapid innovation is reshaping what everyday employees can do with AI. It is no longer just helping people write faster or summarize information; it is becoming a hands-on work companion that can research, reason, build, and take action across business workflows. But as Claude moves from a chat experience to code, Cowork, skills, MCP servers, and agent workflows, the security question changes too: how can teams adopt those capabilities without creating new blind spots and added risk?

Cato AI Security is innovating alongside Claude. We are building the visibility and inline controls customers need as they put AI to work, so security does not have to catch up after adoption has already moved ahead.

1. Extending AI security to Claude with Inference Hooks

Anthropic Inference Hooks give enterprises a native integration point to inspect and enforce policy before prompts and tool calls reach Claude, regardless which tool is being used. This is important because teams do not work in one environment. They write code in Claude Code, collaborate in Claude Cowork, and use Claude across different workflows and endpoints. Until today, partial solutions have forced security teams to choose where they have controls and where they accept a gap.

Immediately following Anthropic’s recent announcement, Cato AI Security extended its own protection across Claude Enterprise experiences, including Claude Chat, Claude Code, and Claude Cowork, without deploying an endpoint agent or requiring network inline access.

This creates a single point of visibility for prompts, agentic interactions, and tool use, helping security teams monitor activity, apply policies, and maintain an audit trail while preserving a seamless user experience.

Moreover, combining Claude Inference Hooks with Cato’s state-of-the-art AI Engine, battle-tested against AI-native risks such as prompt injection and jailbreaks, brings advanced protection across the Claude ecosystem without disrupting how employees work.

2. Govern the skills, MCPs, and tools that give agents the ability to act

Skills are reusable instruction packages that extend what an agent can do, often by connecting it to tools, data sources, or workflows. Together with MCP servers and tools, they give agents access to data and the ability to take action. However, when employees add these capabilities from the internet, poisoned or malicious MCP servers or skills can influence or manipulate an agent through the instructions or data it returns. This is not only theoretical, in one example, a malicious MCP package impersonated a legitimate Postmark email integration and silently BCC’d emails processed by the agent to an attacker-controlled address.

The risk is not limited to malicious integrations. Vulnerabilities have even been found in Anthropic’s official Git MCP server that, when combined with a legitimate Filesystem MCP, could allow an agent to alter files or execute code following a prompt-injection attack. While Anthropic patched the issues before any reported exploitation, this highlights how individually legitimate tools can create an unsafe path when their combined permissions exceed the agent’s intended task.

To support this new agent risk surface, Cato has added visibility and governance for the capabilities agents use. Security teams can understand the risk each agent introduces, then apply policy across the interaction, not only the first prompt.

  • MCP and tool visibility: See the MCP servers and tools available to agents, so security teams can understand the connections and actions that make up each agent’s risk surface.
  • Skill visibility and posture: See all the skills in the environment and assess their posture, helping teams identify capabilities that require review before they are used in a business workflow.
  • Full-lifecycle policy enforcement: Apply runtime policies to the user prompt, AI response, tool input, and tool outputβ€”powered by a state-of-the-art, battle-tested detection engine for AI-native risks such as prompt injection and jailbreaks. Trusted by Fortune 500 companies, it delivers high-fidelity detection at low latency, giving teams one control model for what an agent sees, requests, and does.

Together, these controls help teams govern the information flowing through an agent and the actions it can take, without treating every new tool or skill as a separate security project.

3. Make protection practical to deploy and operate

A security control is not useful if it has to wait for a tenant-wide rollout or leaves the first session on a new device unprotected. Teams also need policy and audit records to show the right client identity, not a subscription identity that obscures who and what acted. And when developers are adopting new agents quickly, security teams need a deployment and troubleshooting path that does not slow them down.

Enforcement has to be practical to deploy, validate, and expand – to enable this, Cato has rolled out the following updates to help teams introduce protection with less friction and more operational control:

  • Scoped rollout and accurate attribution: Apply controls to specific users or groups, while using Cato Scout’s client identity to ensure policies and audit records are tied to the correct endpoint user or device.
  • Protection before first use: Write hook configuration before a supported agent is detected, reducing the chance that the first session on a new device is outside enforcement.
  • Deployment and troubleshooting in the workflow: Push custom Claude Code settings with Scout, install Scout as a native Claude Code plugin, and use scout-debug to verify hook registration inside supported agents.

These improvements turn agent security from a broad switch into a controlled rollout that teams can validate and expand with confidence.

Security controls cannot wait

AI platforms are rolling out features and capabilities quicker than ever before. And employees are adopting these new capabilities – creating blind spots as products are rolled out faster than the controls meant to keep them safe.

Security cannot wait for the next release cycle.

Cato is building and shipping controls right alongside the AI platform development, so security can keep pace as employees and developers put AI to work. Moreover, Cato brings those controls into the same environment teams already use to manage AI security. From a single pane of glass, teams can see AI activity, assess posture, and apply runtime controls across AI usage, applications, and agents. That gives security teams the agility to govern new interactions quickly, with less friction and without adding another tool.

To learn how Cato AI Security secures Claude and the broader AI environment, contact Cato Networks.

Related Topics

Wondering where to begin your SASE journey?

We've got you covered!
Liron Hakim Bobrov

Liron Hakim Bobrov

Product Marketing Manager

Liron Hakim Bobrov is a product marketing manager specializing in AI security. She currently serves as a Product Marketing Manager at Cato Networks, where she helps enterprises navigate the evolving AI risk landscape and implement AI Security solutions with confidence. Previously, she was Senior Director of Product Marketing and Content at Alice, where she led go-to-market strategy, messaging, and content for AI security and Trust & Safety products. She holds an MBA from Tel Aviv University and a B.S.W. from The Hebrew University of Jerusalem.

Read More