AI Coding CLI Launched With Permission Bypass Flags
Detects the usage of command-line flags in AI coding assistant CLIs (such as Claude Code, Amazon Q CLI, and others) that intentionally skip security permissions, bypass approvals, or disable sandbox protections. The rule identifies potential developer activity that may inadvertently reduce the security posture of the development environment.
Microsoft Sentinel (KQL)

