AI Coding Agent Plugin Process Accessing SSH/Cloud Credential Files
Detects instances where AI-assisted coding tools or command-line interfaces spawn scripting runtimes (Node.js, Python) to access sensitive files such as SSH keys, cloud provider credentials, or Kubernetes configurations. This behavior may indicate an AI coding assistant being coerced or misconfigured to exfiltrate secrets from the development environment.
SentinelOne

