AI Agent Runtime Spawning Shell/Interpreter via Tool-Call RCE (CVE-2026-26030)

Detects instances where AI agent host processes (such as Python, .NET, or IIS worker processes) spawn suspicious child processes like command interpreters or common system utilities. This behavior is indicative of potential Remote Code Execution (RCE) via prompt injection, where an AI agent is manipulated into executing arbitrary system commands.