Skip to content

AI agent surface detection

AI coding agents do not only run on laptops. They run on dev boxes, CI runners, jump hosts, and sometimes on the production server itself. What an agent can do on a host is decided by files next to it: the MCP servers it is configured to launch, hooks that run commands automatically, permission settings that switch safety checks off, and instruction files it reads before every task. A repo checkout or a one-line settings change can widen all of that without anything else on the host looking different.

The host agent reports this AI agent surface for each server:

  • Installed agent CLIs - Claude Code, Codex, Gemini CLI, Cursor, Aider and others.
  • MCP servers those agents are configured to launch, with the command or package they run.
  • Agent config files in home directories and in repositories.
  • Risky settings - safety bypass modes, hooks, auto-run tasks, wildcard tool permissions.
  • Secrets stored in agent or MCP config files.

Each report is compared with a human-approved baseline, and anything new or risky is raised as a finding that stays open until a person accepts it. It is the same model as the MCP server monitor, applied to what is on the host rather than what a remote server advertises.

  • A Linux or Windows host running a recent agent version that includes the scanner. macOS is not supported yet.
  • Nothing to install or configure. The scanner is on by default.

Process-execution findings (ai-001 to ai-003) come from the same exec events as other process rules: eBPF on Linux, Sysmon on Windows. They work with any agent that already sends those events.

The scanner runs every 15 minutes (with jitter, so a fleet does not scan at the same moment) and on demand from Scan now on the host’s AI agents tab.

PlatformRoots
LinuxHome directories of users with uid >= 1000, plus /root
WindowsC:\Users\*, except Public and Default
Both/srv, /opt, /var/www, /data when present

Looked up at known locations in each home directory:

ToolFiles
Claude Code.claude/settings.json, .claude/settings.local.json, .claude.json, .claude/agents/, .claude/skills/, .claude/commands/
Cursor.cursor/mcp.json
VS Code / CopilotUser settings.json and mcp.json
Gemini CLI.gemini/settings.json
Codex.codex/config.toml
Windsurf.codeium/windsurf/mcp_config.json
Amazon Q.aws/amazonq/mcp.json
Claude Desktopclaude_desktop_config.json
Continue.continue/config.yaml
Clinecline_mcp_settings.json

Found by a bounded walk of the roots, anywhere a repository is checked out:

.mcp.json .claude/settings.json .claude/settings.local.json
.cursor/mcp.json .cursor/rules/* .cursorrules
.vscode/mcp.json .vscode/tasks.json .gemini/settings.json
.amazonq/mcp.json AGENTS.md CLAUDE.md
GEMINI.md

The walk goes at most 5 levels deep and skips node_modules, .git, vendor, caches, virtualenvs, and build output directories. It stops at 50,000 entries or 5 seconds, whichever comes first, and a report cut short that way is marked truncated.

claude, codex, gemini, cursor-agent, aider, goose, opencode, amp, q, copilot and similar, found on PATH and in common per-user bin directories.

  • Files over 1 MB are skipped and listed as skipped in the report.
  • Symlinks are not followed.
  • The scan is read-only. It never changes or moves a file.

The agent parses each file on the host and sends a structured summary. File contents never leave the host.

SentNever sent
Path, tool, scope (user or repo), owner, size, modification time, SHA-256 of the fileFile contents
MCP server name, transport, command basename, package nameFull URLs - only the host part is sent
Environment variable and header key namesEnvironment variable and header values
Arguments, with values redactedSecret values, or hashes of secret values
Flags: bypass mode, hook count and hook command basenames, folderOpen tasks, wildcard tool allow rules
For each secret: its type and its location in the file (for example mcpServers.postgres.env.PGPASSWORD)
For instruction files: the names of lint rules that matchedThe matching text

Secret detection covers known token shapes (Anthropic, OpenAI, GitHub, AWS, Slack, Stripe and others), connection strings with passwords, JWTs, and any non-empty value under a key named like a token, key, secret, or password.

Findings are security events with a rule ID. ai-001 to ai-003 come from process execution; ai-010 to ai-016 come from the inventory scan.

RuleFindingSeverityTriggered by
ai-001AI agent run with safety checks disabledhighAn agent CLI started with a bypass flag such as --dangerously-skip-permissions, --permission-mode bypassPermissions, --yolo, or --trust-all-tools
ai-002MCP server launchedlowAn MCP server process started (for example through npx or uvx). Visibility only, no alert by default
ai-003Destructive command run by an AI agentcriticalAn rm -rf of a critical path, or an external download, whose parent or grandparent process is an AI agent
ai-010New MCP server configuredmediumAn MCP server entry not in the baseline
ai-011MCP server command, package or URL host changedmediumA known MCP server now launches something else or points at a different host
ai-012Safety bypass enabled in agent settingshighpermissions.defaultMode set to bypassPermissions, Codex approval_policy = "never" with danger-full-access, Gemini yolo, or a wildcard tool allow rule such as Bash(*)
ai-013Hook added to agent settingsmediumA new hook - hooks run commands automatically when the agent acts
ai-014Secret stored in an agent or MCP config filemediumA secret in a config file. Raised once per file and location
ai-015Repo-level agent config appearedmediumA repo .claude/settings.json with hooks, a .vscode/tasks.json with a folderOpen task, or a .mcp.json
ai-016Instruction file with a lint hithighAGENTS.md, CLAUDE.md, GEMINI.md, or a rules file containing hidden Unicode, instruction markers, or references to sensitive paths

The instruction-file lint uses the same rules as the MCP monitor’s suspicious-pattern lint. Only the rule names are sent, never the text.

  • The first report sets the baseline. MCP servers, hooks, and repo-level configs already on a host when the scanner first reports are accepted as they are (trust on first use), so an existing setup does not produce a day of findings.
  • Risky state is flagged even on the first report. Bypass settings (ai-012), stored secrets (ai-014), and instruction-file lint hits (ai-016) are raised on the first report too. A host that was already in bypass mode when you installed the agent still gets flagged.
  • Findings stay open until a person accepts them. On the host’s AI agents tab (under Security, then Servers), accept selected findings, or accept the whole current inventory as the new baseline. Accepting the whole inventory replaces the baseline, so items no longer on the host drop out of it.
  • Accepting is human-only. It works only from a person signed in to AlertKick (web or mobile app). Requests made with API keys, through the hosted MCP connector, or by other automation are refused with 403. An AI agent must not be able to approve its own new tools or permissions.

Findings appear on the Security events page and on the host’s events, and open alerts through the normal detection-to-alert path when the rule’s severity is at or above the account’s minimum severity on Security, then Detections, then Alerting (high by default). Out of the box that means:

  • ai-001, ai-003, ai-012, and ai-016 open alerts.
  • Medium findings (ai-010, ai-011, ai-013, ai-014, ai-015) are recorded but do not page, unless the threshold is lowered.
  • ai-002 is recorded for visibility only.

The rules live under the AI agents category on Security, then Detections, and are enabled by default. Disable a rule or override its severity there; see Customizing detection rules.

MCP server, launch-target, and hook changes (ai-010, ai-011, ai-013) on a host inside a started change are recorded as expected, informational events and added to the baseline automatically. Planned work that adds an MCP server does not need a separate accept.

Bypass settings, secrets, repo-level configs, and instruction lint hits are not covered by a change and are raised as usual.

Security, then AI Agents lists every host with counts of installed CLIs, MCP servers, bypass settings on, stored secrets, and open findings. Filter by tool or by MCP package to answer questions such as “which servers run Claude Code in bypass mode?” or “where is this MCP package configured?”.

The scanner is controlled by the agent setting agent_surface.enabled (default true). Set it to false to stop scanning on a host. Process-execution findings (ai-001 to ai-003) are controlled by their rules on the Detections page, not by this setting.