Internet Infrastructure

"ConoHa VPS byGMO" Bundles Free Feature to Prevent Malicious Program Components from Entering AI Agent Development Environments

Standard Provision of "Guard" Feature from "Takumi byGMO," Enabled with a Single Command

 GMO Internet, Inc. (President & CEO: Tadashi Ito; hereinafter "GMO Internet"), a member of the GMO Internet Group, began, on Friday, September 25, 2026, bundling a dedicated script for the "Guard" feature(※1)free of charge into seven AI agent-related startup script templates for "ConoHa VPS byGMO" (URL: https://vps.conoha.jp/). As a result, users can now enable protection against malicious packages with a single command after building their AI agent execution environment.

 The "Guard" feature is a function of "Takumi byGMO" (URL: https://flatt.tech/takumi), provided by GMO Flatt Security, Inc. (President & CEO: Yasutaka Ide; hereinafter "GMO Flatt Security"), which offers cybersecurity-related businesses for product development organizations.The feature intervenes while program components are being delivered from a package registry(※2)to the development environment, automatically blocking the download of malicious program components (malicious packages).Through this bundling, individual developers and small teams can more easily adopt protective measures without complex configuration.

(※1)"Takumi byGMO" is a service developed and provided by GMO Flatt Security, and the "Guard" feature is the function within it responsible for countering software supply chain attacks.
(※2)A centrally managed service through which developers register and publish program components (software packages) used to assemble programs, and through which other developers can download and use them.

【Background to the Launch】

 With the expanding use of generative AI, it is becoming common in software development for AI to autonomously incorporate open-source program components (software packages).At the same time, the need for countermeasures against "software supply chain attacks"—in which malicious components are mixed into package registries to compromise development or CI/CD environments—is also growing. In response to this situation, use of the "Guard" feature, which prevents the intrusion of malicious packages, has rapidly expanded, and in August 2026 a day was observed on which the number of inspections exceeded 50 million per day(※3). Amid intensifying attacks, in order to enable more people to take countermeasures, GMO Internet has partnered with GMO Flatt Security to bundle the management script for the "Guard" feature into the AI agent-related templates of "ConoHa VPS byGMO." As a result, users can more easily adopt supply chain attack countermeasures at no additional cost after building their AI agent development environment.

(※3)GMO Flatt Security Publishes "Software Supply Chain Threat Report 2026" — Approximately 31,000 Malicious Packages Detected in Half a Year, with Takumi Guard Inspecting Over 50 Million Package Downloads per Day(https://group.gmo/news/article/10179/)

【About the "Guard" Feature】

 The "Guard" feature is "a mechanism that inspects software components before they are received." It intervenes between the package registry and the engineer's development environment, switching package acquisition requests through a transparent proxy to verify, in real time at the point of download, whether a package is malicious. Packages determined to be malicious are automatically blocked before they reach the developer's terminal or CI/CD environment.At the core of this feature is a blocklist independently built and operated by GMO Flatt Security. This blocklist is continuously updated through inspection of all packages published on npm. In addition, GMO Flatt Security's research team continuously verifies and improves inspection accuracy. Unlike mechanisms that retroactively scan already-installed packages, this feature intervenes at the time of installation, thereby preventing the intrusion of malicious packages before it occurs. The package ecosystems supported by the "Guard" feature are npm, pip/uv, RubyGems, Go modules, and Composer(※4).

■Templates Included (7 in Total)(※5)
 The dedicated script for configuring the "Guard" feature is bundled into a total of seven templates: the AI coding agents "Claude Code," "Codex CLI," "OpenCode," and "Antigravity CLI," and the AI task execution agents "OpenClaw," "NanoClaw," and "Hermes Agent."

■Key Features
1. Supply chain attack countermeasures can be introduced with a single command after server setup
 Because the dedicated script is bundled into the startup script that automatically builds the AI agent execution environment, users do not need to separately search for and introduce a countermeasure tool after building their environment. The script automatically detects package managers already installed on the VPS and applies configuration only to those detected, helping to reduce setup time and prevent configuration errors.

2. Users can enable the feature at their own discretion, as needed
 The "Guard" feature is not enabled at the time the startup script is run. It is designed to be enabled only when the user runs the dedicated script as needed.

3. The dedicated script manages everything from status checks to enabling and disabling
 The "Guard" feature is provided as an independent, dedicated script that allows users to check status, enable, register, authenticate, renew, and disable the feature. The main commands are takumi-status, takumi-enable, takumi-register, takumi-login, takumi-renew, and takumi-disable(※6).

4. Two usage modes can be selected according to purpose
 Two modes are available: ① an anonymous mode (takumi-enable) that blocks malicious packages only, without requiring email registration, and ② a mode (takumi-register → takumi-login) in which a token is obtained via email authentication, enabling download tracking and breach notifications. The obtained token can be used in common across all ecosystems supported by the "Guard" feature.

(※4)As of August 2026.
(※5)The templates included are as planned as of September 25, 2026, and are subject to change.
(※6)This is not a resident monitoring process but a configuration applied at the time the command is executed. Therefore, if a new package manager is introduced later, the script must be run again.

【How to Use】

1. Add a server from the "ConoHa VPS byGMO" control panel and select the target AI agent template under "Startup Script."
2. After the server is built, run the bundled dedicated script.
3. To use malicious package blocking only, run takumi-enable.
4. To also use download tracking and breach notifications, complete email authentication with takumi-register, then set the token with takumi-login.

【About Pricing】

 The startup script feature of "ConoHa VPS byGMO" (a feature that automatically executes commands configured when adding a server) is available free of charge. In addition, blocking of malicious program components by the "Guard" feature is also free of charge, regardless of whether the user is an individual or a corporation. Please note that a separate server usage fee for "ConoHa VPS byGMO," on which the templates run, is required. For organizations considering bulk deployment across all devices, a paid bulk setup feature is available through the management tool of "Takumi byGMO."

【Comment from Takashi Yonai, Director, Executive Vice President and Co-CTO, GMO Flatt Security, Inc.】

 In 2026, as attacks targeting development environments and program components have increased, securing the software supply chain has become a challenge common to all developers. In particular, as the use of AI agents advances and vibe coding becomes widely practiced, the number of program components incorporated without the developer's knowledge continues to increase. "Takumi byGMO" has, to date, inspected a vast number of program components on a daily basis, protecting the development and AI usage of many people by swiftly detecting the malicious intent hidden within them. We are truly delighted to be able to deliver greater safety to even more AI users and developers by partnering with "ConoHa VPS byGMO," which also supports the utilization of AI agents. We will continue to combine the strengths of the Group to refine our services dedicated to "watching engineers' backs."

【Comment from Kimihiro Kodama, Senior Managing Executive Officer, GMO Internet, Inc.】

 The GMO Internet Group has set forth the goal of being the "No.1 Corporate Group Creating the Future with AI & Robotics," and is advancing the utilization of AI and the provision of new services for the AI industry. Through "ConoHa VPS byGMO," we have also provided an environment where AI agents can be quickly tried out; however, as their use expands, continuously implementing specialized security measures becomes a major challenge for individual developers and small development teams. We believe that convenience and security are not a matter of choosing one over the other, but should be enhanced together. By incorporating the expertise of GMO Flatt Security, which has high specialization in both AI and security, we will continue to provide an environment in which more people can utilize AI with peace of mind and take on the challenge of creating new value.

【About GMO Flatt Security, Inc.】
(URL:https://flatt.tech)

 Under the mission of "watching engineers' backs," GMO Flatt Security is a Japan-based security professional firm that has supported DX promotion and software development security across industries. Based on insights gained through in-house development of security products, security support for a wide range of companies, and thorough user interviews, the company provides hands-on security services tailored to each individual client organization.

■Engineer-Focused Services for "Watching Engineers' Backs"
・Vulnerability assessments and penetration testing by security engineers: https://flatt.tech/assessment
・"Takumi byGMO," an AI agent specialized in security assessment and software supply chain attack countermeasures: https://flatt.tech/takumi
・"Shisho Cloud byGMO," a continuous cloud security posture management (CSPM) tool for AWS and other cloud environments: https://shisho.dev/ja
・"KENRO byGMO," a cloud-based secure coding learning platform: https://flatt.tech/kenro
※ The company and product names listed are the trademarks or registered trademarks of their respective companies.

【About "ConoHa byGMO"】
(URL:https://www.conoha.jp/)

 "ConoHa byGMO" is a hosting service of the GMO Internet Group, which boasts the No. 1 domestic hosting share(※7). It offers services suited to a wide range of customer needs, including "ConoHa WING," a rental server optimized for blogs and website creation and the fastest in Japan(※8); "ConoHa VPS byGMO," which allows for more freely customized and configured servers; "ConoHa for GAME," aimed at game users and offering free game templates; and "ConoHa AI Canvas," which allows users to enjoy full-fledged AI image generation using only a browser. Thoroughly pursuing "simplicity" and "ease of use" with no initial setup fee, the service is used by a wide range of customers, from first-time server users to sole proprietors and corporations.

(※7)As of August 2026, based on a survey by domaintools.com; the Company's share of the number of domains hosted among major domestic rental server providers as defined by the Company.
(※8)As of May 2026, based on the Company's own research. Among the top 10 services accounting for over 90% of domestic market share, server processing speed under the lowest-tier plan of each service was measured five times using the load testing tools "Apache Bench" and "h2load," and the average values were compared. Domestic market share was calculated based on Webhosting.info and DomainTools.

AI Summary

ConoHa VPS by GMO Bundles Guard-Dedicated Scripts for 7 AI Agent Types at No Charge

Guard verifies malicious packages at the time of download and automatically blocks intrusion into development environments

Starting September 25, 2026; can be enabled optionally with a single command line; free of charge

Inquiries

  • 【Service-Related Inquiries】

    ●GMO Internet, Inc.
    ConoHa Business Division
    Matsui
    Inquiries: [email protected]

    ●GMO Flatt Security, Inc.
    Public Relations
    E-mail: pr@flatt.tech