AI Agent Accessing Local Credential Files
Detects when an AI agent or assistant process attempts to access sensitive local configuration or credential files (e.g., .aws/credentials, .env, id_rsa, service account keys, .netrc) that typically fall outside the scope of its intended function. This behavior is indicative of unauthorized access, potentially due to prompt injection or malicious exploitation of the agent's file system permissions.
YARA-L

