THREATOPS
THREAT OPSThreat News › 13 million tool calls: auditing every AI coding agent action with Elastic Agent

13 million tool calls: auditing every AI coding agent action with Elastic Agent

medelastic_securityPublished 2026-08-11

<p>We gave hundreds of developers an AI agent that can run shell commands, edit files, and call <a href="https://modelcontextprotocol.io">Model Context Protocol (MCP)</a> servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the <a href="https://www.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/ai-coding-agent-audit-cursor-hooks