Every agent step authorized, yet the sequence is an exfiltration path
Electrical-Hall8869 · reddit · 2026-10-01
An agent reads a secret, calls an external endpoint, then writes to a shared location — each step individually authorized, but chained together it's a data exfiltration path. Per-request filtering can't catch it since no single request is the problem; EDR sees the process, DLP sees the payload, neither reconstructs the decision path. Author asks whether anyone is doing session-level behavioral chaining detection.
More from coding & agent
- OCR-ing Every Image in a Twitter Archive to Feed Semantic Search — mimi10v3 · 2026-10-01
- Do cloud agents always end up installing something on the customer's machine? — NoDrummer9540 · 2026-10-01
- xAI reportedly uses Grok Bot agents to build Grok Bot, from design to merged PRs — elonmusk · 2026-10-01
- Codiff 1.15 adds in-editor code editing, ships with a de-bloated VSCode config — cnakazawa · 2026-10-01
- Runway MCP Lands in ChatGPT App Directory: Generate Video From Any Agent — tlakomy · 2026-10-01
- How should always-on agents handle backpressure and stale queues after rate limiting? — daani_maas · 2026-10-01