Metano's SkillTracer Watches the AI Agent's Hands in Real Time

The 2026-founded startup is building a runtime security layer for autonomous AI, a nascent category where Palo Alto Networks and others are already circling.

About Metano

Published

You install a new skill for your AI agent, a tool that promises to summarize a week’s worth of Slack threads. The agent begins its work. In a separate pane, a log begins to populate, not with the summary’s text, but with a granular, second-by-second account of the agent’s actions: which channels it accessed, what files it read, where it attempted to send data. This is the view Metano is selling, a security camera pointed not at a network perimeter, but at the runtime behavior of an autonomous system. The company’s early product, SkillTracer, is built on a simple, unsettling premise: skills lie. The stated purpose of a piece of agentic software, Metano argues, is often a poor predictor of what it actually does when let loose [SkillTracer, retrieved 2024].

The runtime security wedge

Metano’s bet is that securing AI agents requires a fundamentally different approach than securing traditional software or even large language models. Where legacy security tools might scan code or monitor API calls, Metano’s platform aims to observe, assess, and enforce controls at the precise moment an agent takes an action [PERPLEXITY SONAR PRO BRIEF, retrieved 2024]. The company positions itself as a control plane, providing the visibility and context a security team would need to answer a basic question: is this agent doing what it’s supposed to be doing, and nothing else? Their wedge is runtime verification. SkillTracer, for example, continuously compares an agent’s actions against the skill’s declared purpose and the user’s inferred intent, flagging any mismatch [SkillTracer, retrieved 2024]. It’s a shift from securing a static artifact to policing a live, decision-making process.

A crowded field with an early start

Founded in 2026 and based in San Jose, Metano is entering a market that is both embryonic and already attracting serious players. The company lists competitors including Armadin, Trent AI, Aona AI, and Palo Alto Networks’ Prisma AIRS [cbinsights.com, retrieved 2026]. This is a signal that agentic AI security is being recognized as a distinct, necessary category, not just a feature of existing cloud security platforms. Metano’s early founding date, while leaving many details undisclosed, gives it a potential head start in defining the architecture and user expectations for this new layer of defense. With an estimated 11-50 employees [LinkedIn, retrieved 2024], the company is likely in a build-and-validate phase, focused on proving its core runtime detection thesis with early design partners.

Competitor Notable Angle
Armadin Agent security platform
Trent AI Workforce AI security
Aona AI Workforce AI security platform
Palo Alto Networks (Prisma AIRS) Integrated AI security suite from a market leader
Selected competitors in the agentic AI security space [cbinsights.com, retrieved 2026].

The validation gap

The primary challenge for Metano is the same one facing every pioneer: proving that the problem it solves is urgent and widespread enough to support a standalone business. The market for autonomous AI agents, while growing rapidly, is still in its formative stages. Enterprise security teams, the logical buyers for Metano’s platform, are currently preoccupied with securing foundational models and preventing data leakage in chatbots. Convincing them to allocate budget and personnel to secure a class of software that may not yet be widely deployed in their organizations is a significant go-to-market hurdle. Furthermore, the competitive landscape includes well-funded incumbents like Palo Alto Networks, which could choose to bundle similar runtime agent security into its broader Prisma cloud security suite, potentially squeezing out pure-play startups.

The company’s near-term trajectory will likely hinge on a few key signals:

  • Early lighthouse customers. Securing a named, credible enterprise that will publicly discuss using Metano to secure production AI agents.
  • Technical differentiation. Demonstrating that its runtime detection catches threats or policy violations that static analysis and intent-scanning miss.
  • Funding and partnerships. Announcing a seed or Series A round to scale the team, or a technology partnership with a major agent platform provider.

Metano’s entire proposition rests on a cultural shift in how we think about software trust. For decades, security has been about verifying the box before you open it,checking signatures, scanning for malware. Autonomous agents represent a box that opens itself, makes decisions, and takes actions in real time. The implicit question Metano is asking, and attempting to answer with a dashboard and an alert log, is whether we can ever truly trust an AI we cannot watch. The company is betting that in the agentic future, continuous, skeptical observation will be the only form of trust that matters.

Sources

  1. [SkillTracer, retrieved 2024] SkillTracer - Skills lie. We stop that. | https://labs.metano.ai/scanner
  2. [PERPLEXITY SONAR PRO BRIEF, retrieved 2024] PERPLEXITY SONAR PRO BRIEF
  3. [cbinsights.com, retrieved 2026] Metano - Products, Competitors, Financials, Employees, Headquarters Locations | https://www.cbinsights.com/company/metano-1
  4. [LinkedIn, retrieved 2024] Metano | https://www.linkedin.com/company/metanocc

Read on Startuply.vc