Every AI agent and MCP location
Everything a repository can hand a coding agent, the exact paths Cordon reads for each, and every rule that judges them. Rendered from the detector itself, so a location added to the code appears here, and one that is not read never does. The walkthrough is tutorial 18.
instruction files ──┐ skills, commands ───┤ settings and hooks ─┼──► read, never run ──► Cordon's agent rules MCP configurations ─┤ Agent Threat Rules files run on open ──┤ intent, offline CI agent actions ───┘ the judge, if asked
Text an agent reads as its instructions. Checked for hidden characters, injection wording, remote instructions, what the text asks for, and the Agent Threat Rules.
| Path | Read by |
|---|---|
CLAUDE.md | |
CLAUDE.local.md | |
AGENTS.md | Codex, Amp and AGENTS.md readers |
AGENT.md | Codex, Amp and AGENTS.md readers |
GEMINI.md | |
.cursorrules | |
.cursor/rules/** | |
.windsurfrules | |
.windsurf/rules/** | |
.clinerules | |
.clinerules/** | |
.github/copilot-instructions.md | |
.github/instructions/** | |
.github/prompts/** | |
SKILL.md | Claude Code and other skill readers |
.claude/commands/** | |
.claude/agents/** | |
.claude/skills/** | |
.claude/output-styles/** | |
.github/chatmodes/** | |
.github/agents/** | |
.cursor/commands/** | |
.gemini/commands/** | |
.opencode/agent/** | |
.opencode/command/** | |
.windsurf/workflows/** | |
.kiro/steering/** | |
.amazonq/rules/** | |
.junie/** | |
.augment-guidelines | |
.augment/rules/** | |
.trae/rules/** | |
.roo/rules/** | |
.roo/rules-*/** | |
.continue/rules/** | |
.continue/prompts/** | |
.rules | |
.goosehints |
Configuration that decides what an agent may do, and hooks it runs on its own: permissions granted, commands run on events, approval switched off.
| Path | Read by |
|---|---|
.claude/settings.json | |
.claude/settings.local.json | |
managed-settings.json | |
hooks/hooks.json | |
.cursor/hooks.json | |
.windsurf/hooks.json | |
.gemini/settings.json | |
.kiro/hooks/* | |
.codex/config.toml |
Every MCP configuration dialect. Each local server is resolved to the exact package it launches and read from the registry tarball; each remote one, with --online, is asked what it serves now (tutorial 18).
| Path | Read by |
|---|---|
.mcp.json | every MCP client that reads a project file |
.cursor/mcp.json | |
.vscode/mcp.json | |
.gemini/settings.json | |
.windsurf/mcp.json | |
.roo/mcp.json | |
claude_desktop_config.json | |
mcp.json | MCP clients |
cline_mcp_settings.json | |
.zed/settings.json | |
opencode.json | |
opencode.jsonc | |
.codex/config.toml | |
.continue/config.yaml | |
.continue/mcpServers/* |
Commands an editor or agent runs without anyone typing them: tasks set to run on open, dev-container lifecycle commands, background-agent setup.
| Path | Read by |
|---|---|
.vscode/tasks.json | |
.devcontainer/devcontainer.json | |
.devcontainer.json | |
.devcontainer/*/devcontainer.json | |
.cursor/environment.json |
Extensions and plugins a repository asks to have installed, checked against the marketplaces' own malware and impersonation verdicts.
| Path | Read by |
|---|---|
.vscode/extensions.json | |
.devcontainer.json | |
.devcontainer/devcontainer.json | |
.devcontainer/*/devcontainer.json | |
*.code-workspace | |
.gitpod.yml | Gitpod |
.gitpod.yaml | Gitpod |
Brewfile | |
.claude-plugin/marketplace.json |
Workflow steps that run a coding agent, checked for untrusted triggers, write permissions and broad tools.
| Action | Agent |
|---|---|
anthropics/claude-code-action | |
anthropics/claude-code-base-action | |
google-github-actions/run-gemini-cli | |
openai/codex-action |
cordon-scanner agent inventory reads these, and only these; agent report sends the list, never a file's contents. Paths shown for Linux; on macOS and Windows the application-support folder is used.
| Path | Tool | Kind |
|---|---|---|
~/.claude/settings.json | settings | |
~/.claude/settings.local.json | settings | |
~/.claude/CLAUDE.md | instructions | |
~/.claude.json | claude-json | |
~/.config/Claude/claude_desktop_config.json | claude-desktop | |
~/.cursor/mcp.json | ||
~/.codeium/windsurf/mcp_config.json | ||
~/.gemini/settings.json | gemini-cli | |
~/.gemini/GEMINI.md | gemini-cli | instructions |
~/.config/Code/User/settings.json | settings | |
~/.config/Code/User/mcp.json | ||
~/.codex/config.toml | codex-toml | |
~/.codex/AGENTS.md | instructions | |
~/.npmrc | npmrc | |
~/.config/pip/pip.conf | ||
~/.pip/pip.conf |
46 rules of Cordon's own, beside the Agent Threat Rules (tutorial 28 lists those too).
| Rule | Severity | What it catches |
|---|---|---|
MALWARE.AGENT.AUTORUN.001 | critical | A command an editor or agent runs on its own attacks the machine |
MALWARE.AGENT.HOOK_EXFIL.001 | critical | An agent hook that sends credentials away or opens a remote shell |
MALWARE.AGENT.HOOK_FETCH_EXEC.001 | critical | An agent hook that fetches and executes remote code |
MALWARE.EXTENSION.KNOWN.001 | critical | An editor extension is a recorded malicious release |
MALWARE.EXTENSION.REMOVED.001 | critical | A recommended or vendored editor extension was removed from the Marketplace as malware |
OPERATIONAL.MCP.UNRESOLVED | info | An MCP server package was not examined |
POLICY.AGENT.AUTO_APPROVE.001 | high | Agent confirmations switched off in committed settings |
POLICY.AGENT.MCP_BROAD_SCOPE.001 | medium | A filesystem MCP server given the whole disk or home directory |
POLICY.AGENT.WIDE_DIRECTORY.001 | medium | Agent given the whole disk or home directory to work in |
POLICY.AGENT.WILDCARD_PERMISSION.001 | medium | Agent permissions allow any shell command |
SECRET.MCP.INLINE_CREDENTIAL.001 | high | A credential written inline in an MCP configuration |
SUSPECT.AGENT.API_REDIRECT.001 | high | Agent API traffic redirected to a host that is not the provider |
SUSPECT.AGENT.ATR.AGENT_MANIPULATION.001 | medium | Text that impersonates an agent or hijacks the agent's task |
SUSPECT.AGENT.ATR.CONTEXT_EXFILTRATION.001 | medium | Text that asks an agent to move secrets or context off the machine |
SUSPECT.AGENT.ATR.DATA_POISONING.001 | medium | Text that plants triggers or false facts for an agent |
SUSPECT.AGENT.ATR.EXCESSIVE_AUTONOMY.001 | medium | Text that asks an agent to act without the user's confirmation |
SUSPECT.AGENT.ATR.MODEL_ABUSE.001 | medium | Text that turns an agent toward abuse of the model |
SUSPECT.AGENT.ATR.MODEL_SECURITY.001 | medium | Text that targets the model's weights or safety |
SUSPECT.AGENT.ATR.PRIVILEGE_ESCALATION.001 | medium | Text that asks an agent to widen its own permissions |
SUSPECT.AGENT.ATR.PROMPT_INJECTION.001 | medium | Text that tries to override an agent's instructions |
SUSPECT.AGENT.ATR.SKILL_COMPROMISE.001 | medium | A skill or plugin shaped like a known compromise |
SUSPECT.AGENT.ATR.TOOL_POISONING.001 | medium | Text that turns a tool into a channel for steering the agent |
SUSPECT.AGENT.CI_PROMPT_INJECTION.001 | high | Untrusted event text passed straight into an agent's prompt |
SUSPECT.AGENT.CI_UNTRUSTED_TRIGGER.001 | high | An AI agent in CI reads text an outsider can write |
SUSPECT.AGENT.CREDENTIAL_EXFIL.001 | critical | Agent instructions that move credentials somewhere |
SUSPECT.AGENT.FETCH_EXEC.001 | high | Agent instructions that fetch and execute remote code |
SUSPECT.AGENT.HIDDEN_TEXT.001 | high | Hidden characters in an agent instruction file |
SUSPECT.AGENT.HOOK.001 | medium | An agent hook committed to the repository |
SUSPECT.AGENT.INJECTION_TEXT.001 | medium | Instruction-like text aimed at a coding agent |
SUSPECT.AGENT.INTENT.001 | high | Text that tells the agent to act against its user |
SUSPECT.AGENT.INTENT_CHAINED.001 | high | Agent instructions that send the agent to a file that acts against its user |
SUSPECT.AGENT.PLUGIN_SOURCE.001 | high | Agent plugins installed from an unverified source |
SUSPECT.AGENT.REMOTE_INSTRUCTIONS.001 | medium | An agent instruction file tells the agent to fetch and follow remote text |
SUSPECT.AGENT.SENSITIVE_IMPORT.001 | high | An agent instruction file imports a credential file |
SUSPECT.EXTENSION.LOOKALIKE.001 | medium | A recommended editor extension imitates a popular one |
SUSPECT.EXTENSION.MALICIOUS_VERSIONS.001 | low | A named editor extension has had malicious releases |
SUSPECT.EXTENSION.REMOVED.001 | high | A recommended or vendored editor extension was removed from the Marketplace |
SUSPECT.MCP.CONTAINER_HOST_ACCESS.001 | high | An MCP server's container is given the host |
SUSPECT.MCP.ENV_INJECTION.001 | high | An MCP server's environment loads code into it before it starts |
SUSPECT.MCP.INSECURE_TRANSPORT.001 | high | A remote MCP server over plain HTTP |
SUSPECT.MCP.LOOKALIKE.001 | high | An MCP server package named like a popular one |
SUSPECT.MCP.SHELL_LAUNCH.001 | high | An MCP server launched through a shell that fetches code |
SUSPECT.MCP.TOOL_DESCRIPTION.001 | high | A tool in this repository's MCP server instructs the agent |
SUSPECT.MCP.UNPINNED.001 | medium | An MCP server launched from an unpinned package |
SUSPECT.MCP.UNTRUSTED_REMOTE.001 | high | A remote MCP server on a tunnel, paste or interaction host |
VULNERABLE.AGENT.ACTION_VERSION.001 | high | An AI agent action below its security fix |
Agent Threat Rules findings are reported in these categories: agent-manipulation, context-exfiltration, data-poisoning, excessive-autonomy, model-abuse, model-security, privilege-escalation, prompt-injection, skill-compromise, tool-poisoning.
Next: 28 · Every rule.