AI Agent Accessing Local Credential Files

Detects when an AI agent or assistant process attempts to access sensitive local configuration or credential files (e.g., .aws/credentials, .env, id_rsa, service account keys, .netrc) that typically fall outside the scope of its intended function. This behavior is indicative of unauthorized access, potentially due to prompt injection or malicious exploitation of the agent's file system permissions.