AI Rules
Overview
Section titled “Overview”Evidence: AI Rules
Description: Parse AI tool rules, instructions, and ignore/indexing files
Category: AI
Platform: linux
Short Name: airule
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”Instruction files such as CLAUDE.md, AGENTS.md, .cursorrules, Copilot instructions, and AI ignore/indexing files persist standing guidance for coding assistants. They can inject attacker-controlled directives or hide files from AI review.
Data Collected
Section titled “Data Collected”This collector gathers structured data about AI rules and instruction files, including path, type, SHA-256, size, and a bounded redacted excerpt.
Collection Method
Section titled “Collection Method”This collector uses the AI artifact scanner across user homes and development roots. Full rule bodies are copied to Content; Case.db stores metadata plus a bounded redacted excerpt.
Forensic Value
Section titled “Forensic Value”Surfaces persistent prompt-injection directives and anti-forensics exclusions that can hide malicious files from AI review or steer agent behavior across sessions.