Security practitioners are increasingly advocating syscall-level visibility for AI agents and other untrusted workloads because application-layer logs and telemetry can be manipulated or suppressed after compromise. One proposal argues that prompt-injected agents can be instructed to “act quietly,” making orchestrator and in-app observability unreliable; by contrast, real-world actions still manifest as kernel syscalls such as open(), connect(), and execve(). The recommended control point is eBPF-based tracing (optionally scoped with cgroups) to detect anomalous behaviors like unexpected outbound connections, access to credential files (e.g., open() on sensitive paths), or suspicious process execution (e.g., spawning bash/curl), enabling alerting independent of what the agent reports.
Related research on Python supply-chain risk reports that a large share of PyPI malware executes at install time (e.g., via setup.py or post-install hooks), creating a monitoring gap in many CI pipelines. A proof-of-concept sandbox, KEIP, uses BPF LSM hooks to monitor the pip process tree and enforce an install-time network policy by whitelisting connect() destinations (e.g., only allowing traffic to package repositories), with the author claiming it blocked active C2/exfiltration attempts across tested samples on kernels 5.8+ with BTF. Together, the work highlights a common defensive theme: kernel-level eBPF/LSM controls can provide tamper-resistant observability and policy enforcement for both AI-agent runtimes and package installation workflows where user-space controls may be bypassed or start too late.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
A March 2026 analysis examined Anthropic’s Claude Code Auto Mode as a response to failing per-action human approvals, citing data that users approve 93% of prompts and that the model-based safeguard still misses 17% of dangerous overeager actions. The write-up argued that enterprises should not treat human-in-the-loop approval as a primary control and should pair probabilistic monitoring with deterministic sandboxing and hard boundaries.
Sysdig Threat Research Team analyzed AI coding agents including Claude Code, Gemini CLI, and Codex CLI on developer endpoints and CI/CD systems, arguing that kernel- or syscall-level monitoring is needed because the agents repeatedly spawn shells, read files, and make network connections with user privileges. The team said it built Falco and Sysdig behavioral detections for agent installation, unauthorized access to agent config directories, sensitive file reads, and unsafe launch-flag bypasses.
An analysis of 12 production multi-agent deployments found that 34% of failures in OpenAI-compatible environments were caused by contract boundary violations, including unauthorized tool use, budget overruns, and invalid parameters. The study contrasted this with a kernel-enforced tool-allowlist deployment that recorded zero such violations during the test window.
A separate post argued that prompt-injected AI agents can tamper with or suppress their own logs, making application-layer observability unreliable, and proposed kernel-level syscall monitoring with eBPF and cgroup filtering instead. The author said they built and published an open-source tool called Azazel to validate this approach for detecting behaviors such as exfiltration, credential access, and shell spawning.
The author released KEIP as an open-source proof of concept for install-time enforcement during pip installs on Linux. KEIP uses BPF LSM hooks to restrict outbound network connections from the pip process tree to PyPI only, and the author reported it blocked all active C2 and exfiltration attempts observed in the tested subset.
An analysis of the QUT-DV25 malware dataset, covering about 14,000 malicious Python packages, found that many samples execute payloads during installation via setup.py or post-install scripts, allowing them to evade typical CI and runtime defenses. The write-up states that 56% of the malware in the dataset runs at install time.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
resilientcyber.io
Open sourcesysdig.com
Open sourcewebflow.sysdig.com
Open sourcethecolony.cc
Open sourcereddit.com
Open sourcenews.ycombinator.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.