Partnership addresses software vulnerabilities within AI agent environments, extending protection beyond isolation and access controls
NanoClaw, the secure open-source AI agent framework, and Echo, a company specializing in vulnerability-free software infrastructure, have announced a partnership to strengthen the security of AI agent runtime environments. The collaboration introduces a hardened runtime designed to protect AI agents from software vulnerabilities in the browsers, libraries and system components they rely on.
According to the companies, the new runtime makes NanoClaw the first open-source AI agent framework to offer a hardened execution environment that secures not only the agent itself, but also the underlying software stack. NanoClaw has gained significant traction since its open-source launch, with more than 30,000 GitHub stars and over 250,000 downloads. The framework is used by practitioners at companies including Amazon, Google, Meta, Gap, SentinelOne and Accenture.
As AI agents become increasingly responsible for browsing the web, opening files, executing code and interacting with enterprise applications, the software environments they operate in have emerged as a growing attack surface. While sandboxing and isolation limit an agent’s access to sensitive resources, they do not eliminate vulnerabilities within browsers, parsers, language runtimes and other software components. Exploiting these weaknesses could allow attackers to gain access to an agent’s data, memory or credentials.
“Modern prompt injection attacks increasingly resemble social engineering,” said Gavriel Cohen, co-founder and CEO of NanoCo, the company behind NanoClaw. “An innocent-looking webpage or document can exploit an unpatched browser or parser vulnerability, compromising the agent. NanoClaw already provides isolation, access controls and human approval for sensitive actions. Our partnership with Echo extends that protection by ensuring the software environment itself is free of known vulnerabilities.”
The hardened runtime was jointly developed by the two companies. NanoClaw provides the secure agent framework, isolation capabilities and policy enforcement, while Echo rebuilds the underlying software environment using only the components required for agent operation. The companies say this approach reduces the number of known software vulnerabilities from thousands to nearly zero while maintaining compatibility with the tools developers expect.
The runtime includes essential components such as Chromium, Node.js, Bun, Git, Curl and other development tools. It is hosted and maintained by Echo, allowing NanoClaw users to enable the hardened environment during setup at no additional cost, while developers who prefer to build their own runtime locally can continue to do so.
Echo’s platform continuously monitors newly disclosed software vulnerabilities and uses AI-driven automation to identify affected components, develop or locate patches, validate compatibility and prepare updates for human review. The company says this enables it to maintain secure software artifacts across containers, operating system packages and software libraries while reducing software supply chain risk.
NanoClaw was launched by Tel Aviv-based NanoCo in 2026 as an open-source framework for secure AI agents. The platform provides sandboxed execution environments, policy-based access controls, runtime credential management, human approval for sensitive actions and full auditability.
Echo develops AI-powered infrastructure designed to eliminate known software vulnerabilities before they reach production environments. Founded by Eilon Elhadad and Eylam Milner, both veterans of Israel’s Unit 8200 and the Israeli Air Force’s Ofek unit, the company previously built software supply chain security startup Argon, which was acquired by Aqua Security. Echo has raised $50 million since its founding and serves customers including Varonis, EDB, Webflow and UiPath.
Photo: Ran Bergman
Israeli startup Modus has emerged from stealth with a $10 million seed round led by…
Series C funding led by One Peak brings total investment in the company to $160…
Industry-leading product line card increased by more than 373,000 products last quarter THIEF RIVER FALLS,…
Infineon Technologies has announced that its SEMPER™ NOR Flash memory has been qualified for ASPEED…
Enterprise demand and AI security adoption drive continued global expansion Cato Networks has announced that…
The Nasdaq-listed company says its platform handled more than 1.3 billion playback sessions during the…