AI agent surface detection
AI coding agents do not only run on laptops. They run on dev boxes, CI runners, jump hosts, and sometimes on the production server itself. What an agent can do on a host is decided by files next to it: the MCP servers it is configured to launch, hooks that run commands automatically, permission settings that switch safety checks off, and instruction files it reads before every task. A repo checkout or a one-line settings change can widen all of that without anything else on the host looking different.
The host agent reports this AI agent surface for each server:
- Installed agent CLIs - Claude Code, Codex, Gemini CLI, Cursor, Aider and others.
- MCP servers those agents are configured to launch, with the command or package they run.
- Agent config files in home directories and in repositories.
- Risky settings - safety bypass modes, hooks, auto-run tasks, wildcard tool permissions.
- Secrets stored in agent or MCP config files.
Each report is compared with a human-approved baseline, and anything new or risky is raised as a finding that stays open until a person accepts it. It is the same model as the MCP server monitor, applied to what is on the host rather than what a remote server advertises.
Requirements
Section titled “Requirements”- A Linux or Windows host running a recent agent version that includes the scanner. macOS is not supported yet.
- Nothing to install or configure. The scanner is on by default.
Process-execution findings (ai-001 to ai-003) come from the same
exec events as other process rules: eBPF on Linux, Sysmon on Windows.
They work with any agent that already sends those events.
What is scanned
Section titled “What is scanned”The scanner runs every 15 minutes (with jitter, so a fleet does not scan at the same moment) and on demand from Scan now on the host’s AI agents tab.
| Platform | Roots |
|---|---|
| Linux | Home directories of users with uid >= 1000, plus /root |
| Windows | C:\Users\*, except Public and Default |
| Both | /srv, /opt, /var/www, /data when present |
Per-user agent files
Section titled “Per-user agent files”Looked up at known locations in each home directory:
| Tool | Files |
|---|---|
| Claude Code | .claude/settings.json, .claude/settings.local.json, .claude.json, .claude/agents/, .claude/skills/, .claude/commands/ |
| Cursor | .cursor/mcp.json |
| VS Code / Copilot | User settings.json and mcp.json |
| Gemini CLI | .gemini/settings.json |
| Codex | .codex/config.toml |
| Windsurf | .codeium/windsurf/mcp_config.json |
| Amazon Q | .aws/amazonq/mcp.json |
| Claude Desktop | claude_desktop_config.json |
| Continue | .continue/config.yaml |
| Cline | cline_mcp_settings.json |
Repo-level files
Section titled “Repo-level files”Found by a bounded walk of the roots, anywhere a repository is checked out:
.mcp.json .claude/settings.json .claude/settings.local.json.cursor/mcp.json .cursor/rules/* .cursorrules.vscode/mcp.json .vscode/tasks.json .gemini/settings.json.amazonq/mcp.json AGENTS.md CLAUDE.mdGEMINI.mdThe walk goes at most 5 levels deep and skips node_modules, .git,
vendor, caches, virtualenvs, and build output directories. It stops
at 50,000 entries or 5 seconds, whichever comes first, and a report cut
short that way is marked truncated.
Installed CLIs
Section titled “Installed CLIs”claude, codex, gemini, cursor-agent, aider, goose,
opencode, amp, q, copilot and similar, found on PATH and in
common per-user bin directories.
Limits
Section titled “Limits”- Files over 1 MB are skipped and listed as skipped in the report.
- Symlinks are not followed.
- The scan is read-only. It never changes or moves a file.
What is sent, and what is never sent
Section titled “What is sent, and what is never sent”The agent parses each file on the host and sends a structured summary. File contents never leave the host.
| Sent | Never sent |
|---|---|
| Path, tool, scope (user or repo), owner, size, modification time, SHA-256 of the file | File contents |
| MCP server name, transport, command basename, package name | Full URLs - only the host part is sent |
| Environment variable and header key names | Environment variable and header values |
| Arguments, with values redacted | Secret values, or hashes of secret values |
Flags: bypass mode, hook count and hook command basenames, folderOpen tasks, wildcard tool allow rules | |
For each secret: its type and its location in the file (for example mcpServers.postgres.env.PGPASSWORD) | |
| For instruction files: the names of lint rules that matched | The matching text |
Secret detection covers known token shapes (Anthropic, OpenAI, GitHub, AWS, Slack, Stripe and others), connection strings with passwords, JWTs, and any non-empty value under a key named like a token, key, secret, or password.
Findings
Section titled “Findings”Findings are security events with a
rule ID. ai-001 to ai-003 come from process execution; ai-010 to
ai-016 come from the inventory scan.
| Rule | Finding | Severity | Triggered by |
|---|---|---|---|
ai-001 | AI agent run with safety checks disabled | high | An agent CLI started with a bypass flag such as --dangerously-skip-permissions, --permission-mode bypassPermissions, --yolo, or --trust-all-tools |
ai-002 | MCP server launched | low | An MCP server process started (for example through npx or uvx). Visibility only, no alert by default |
ai-003 | Destructive command run by an AI agent | critical | An rm -rf of a critical path, or an external download, whose parent or grandparent process is an AI agent |
ai-010 | New MCP server configured | medium | An MCP server entry not in the baseline |
ai-011 | MCP server command, package or URL host changed | medium | A known MCP server now launches something else or points at a different host |
ai-012 | Safety bypass enabled in agent settings | high | permissions.defaultMode set to bypassPermissions, Codex approval_policy = "never" with danger-full-access, Gemini yolo, or a wildcard tool allow rule such as Bash(*) |
ai-013 | Hook added to agent settings | medium | A new hook - hooks run commands automatically when the agent acts |
ai-014 | Secret stored in an agent or MCP config file | medium | A secret in a config file. Raised once per file and location |
ai-015 | Repo-level agent config appeared | medium | A repo .claude/settings.json with hooks, a .vscode/tasks.json with a folderOpen task, or a .mcp.json |
ai-016 | Instruction file with a lint hit | high | AGENTS.md, CLAUDE.md, GEMINI.md, or a rules file containing hidden Unicode, instruction markers, or references to sensitive paths |
The instruction-file lint uses the same rules as the MCP monitor’s suspicious-pattern lint. Only the rule names are sent, never the text.
The approved baseline
Section titled “The approved baseline”- The first report sets the baseline. MCP servers, hooks, and repo-level configs already on a host when the scanner first reports are accepted as they are (trust on first use), so an existing setup does not produce a day of findings.
- Risky state is flagged even on the first report. Bypass settings
(
ai-012), stored secrets (ai-014), and instruction-file lint hits (ai-016) are raised on the first report too. A host that was already in bypass mode when you installed the agent still gets flagged. - Findings stay open until a person accepts them. On the host’s AI agents tab (under Security, then Servers), accept selected findings, or accept the whole current inventory as the new baseline. Accepting the whole inventory replaces the baseline, so items no longer on the host drop out of it.
- Accepting is human-only. It works only from a person signed in to
AlertKick (web or mobile app). Requests made with API keys, through the
hosted MCP connector, or by other
automation are refused with
403. An AI agent must not be able to approve its own new tools or permissions.
Alerts and rule settings
Section titled “Alerts and rule settings”Findings appear on the Security events page and on the host’s events, and open alerts through the normal detection-to-alert path when the rule’s severity is at or above the account’s minimum severity on Security, then Detections, then Alerting (high by default). Out of the box that means:
ai-001,ai-003,ai-012, andai-016open alerts.- Medium findings (
ai-010,ai-011,ai-013,ai-014,ai-015) are recorded but do not page, unless the threshold is lowered. ai-002is recorded for visibility only.
The rules live under the AI agents category on Security, then Detections, and are enabled by default. Disable a rule or override its severity there; see Customizing detection rules.
Change control
Section titled “Change control”MCP server, launch-target, and hook changes (ai-010, ai-011,
ai-013) on a host inside a started
change are recorded as expected,
informational events and added to the baseline automatically. Planned
work that adds an MCP server does not need a separate accept.
Bypass settings, secrets, repo-level configs, and instruction lint hits are not covered by a change and are raised as usual.
Fleet view
Section titled “Fleet view”Security, then AI Agents lists every host with counts of installed CLIs, MCP servers, bypass settings on, stored secrets, and open findings. Filter by tool or by MCP package to answer questions such as “which servers run Claude Code in bypass mode?” or “where is this MCP package configured?”.
Turning it off
Section titled “Turning it off”The scanner is controlled by the agent setting agent_surface.enabled
(default true). Set it to false to stop scanning on a host.
Process-execution findings (ai-001 to ai-003) are controlled by
their rules on the Detections page, not by this setting.
Next steps
Section titled “Next steps”- MCP server monitoring for the same baseline model applied to remote MCP servers
- Security events for reading the stream
- Customizing detection rules for per-rule severity and enablement
- Change tracking and change control for planned changes