Skills, MCP servers, plugins, and extensions pull in from GitHub and public registries, running with developer credentials, spawning processes, and reading source code and secrets. Dizzy gives your security team the visibility and controls to catch a problem before it becomes a breach.

Claude Code, Cursor, GitHub Copilot, Codex, and similar tools extend themselves at runtime. Each extension is an untrusted code execution path your security team has no visibility into.
Skills and MCP servers pull in from GitHub and public registries with no ownership verification, no signing, and no security review. Packages can be swapped out after your team approved them.
Extensions run with the developer's credentials. They can read source code, credentials, and cloud configs, execute shell commands, spawn processes, and send data to external hosts.
Skills and extensions can be installed and running before your security team knows they exist. Malicious behavior is often time-delayed or condition-triggered, so static review won't catch it.
Dizzy covers the skills, MCP servers, plugins, and extensions that existing security tools were never designed to handle.
Know every agent, extension, and tool active across your developer endpoints.
Surface threats that file scanning and reputation checks are blind to.
Set policy and act on findings without getting in your engineers' way.
One place to see what agents are running, what they found, and what to do about it, across Claude Code, Cursor, Copilot, and more.
Real attacks, disclosed responsibly. No target names. Just the technique and what it means for your team.
Talk to us about what's running on your endpoints today.