Skip to content

AI Agents

Evidence: AI Agents
Description: Parse custom AI agent definitions and autonomy settings
Category: AI
Platform: macos
Short Name: aiagent
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Claude Code, Cursor, and similar tools store custom agent definitions that control tools, permission modes, MCP servers, and standing instructions. A poisoned agent definition can grant broad tool access or persist hidden automation.

This collector gathers structured data about custom AI agent definitions, including agent path, tools, permission mode, MCP servers, and bounded instruction excerpts.

This collector parses YAML frontmatter and bounded markdown bodies from project and global agent directories, preserving raw sources in Content.

Identifies custom agents with broad tool access, permission bypass, embedded hooks, or malicious instructions that can steer AI tool execution without an interactive prompt.