AI Agent API POST with Tool-Call JSON Embedding Shell Commands
Detects malicious shell commands or scripts (e.g., bash, powershell, curl, wget) embedded within HTTP POST request bodies that appear to be AI agent tool-call payloads. This activity is indicative of prompt injection or AI tool-use exploitation attempts designed to execute arbitrary code on the underlying host or container.
Suricata

