Every agent step authorized, yet the sequence is an exfiltration path

Electrical-Hall8869 · reddit · 2026-10-01

An agent reads a secret, calls an external endpoint, then writes to a shared location — each step individually authorized, but chained together it's a data exfiltration path. Per-request filtering can't catch it since no single request is the problem; EDR sees the process, DLP sees the payload, neither reconstructs the decision path. Author asks whether anyone is doing session-level behavioral chaining detection.

Original post →

More from coding & agent

coding & agent channel →