AI Agents
Overview
Section titled “Overview”Evidence: AI Agents
Description: Parse custom AI agent definitions and autonomy settings
Category: AI
Platform: windows
Short Name: aiagent
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”Claude Code, Cursor, and similar tools store custom agent definitions that control tools, permission modes, MCP servers, and standing instructions. A poisoned agent definition can grant broad tool access or persist hidden automation.
Data Collected
Section titled “Data Collected”This collector gathers structured data about custom AI agent definitions, including agent path, tools, permission mode, MCP servers, and bounded instruction excerpts.
Collection Method
Section titled “Collection Method”This collector parses YAML frontmatter and bounded markdown bodies from project and global agent directories, preserving raw sources in Content.
Forensic Value
Section titled “Forensic Value”Identifies custom agents with broad tool access, permission bypass, embedded hooks, or malicious instructions that can steer AI tool execution without an interactive prompt.