THREAT OPS › Threat News › 13 million tool calls: auditing every AI coding agent action with Elastic Agent
13 million tool calls: auditing every AI coding agent action with Elastic Agent
<p>We gave hundreds of developers an AI agent that can run shell commands, edit files, and call <a href="https://modelcontextprotocol.io">Model Context Protocol (MCP)</a> servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the <a href="https://www.
MITRE ATT&CK techniques
Indicators of compromise
- https://modelcontextprotocol.iourl
- https://cursor.com/docs/agent/hooksurl
- https://cursor.com/docs/agent/hooks#cloud-distribution-enterprise-onlyurl