Skip to main content

Behavioral security
for the agentic era.

The behavioral security platform for AI agents. Quint watches agents at the OS level, scores their actions in real time with no LLM in the path, and enforces the verdict at the edge, on the device itself.

Overview
Platform

See everything your agents do.

Fleet-wide visibility into risk scores, behavioral baselines, and anomaly detection. One pane of glass.

Why now

Agents are already at work. Security isn’t.

Token made for
custom domains
Token scope
any operation
Asked to delete
no
API calls
1
Elapsed
09.0 s
Restored
within an hour, by Railway
Directed by
a human attacker
Executed by
AI agents
Techniques
50+ MITRE ATT&CK
Novel zero-day
none needed
Elapsed
under 10 h
Sandbox
escaped · zero-day
Egress
Debug-shell binaries
closed
Resolver patching
closed
DNS rewrites
closed
/etc/hosts pinning
closed
CORS relay
closed

01The Register · 27 Apr 2026 · Schematic

9 seconds

A Cursor agent deleted a company’s production database and the backups stored with it, on a token made for managing domains.

Read the report

The public record, to 12 Sep 2026: 71 reports

  1. 8 Aug 2024: Living off Microsoft Copilot (Black Hat). Zenity showed M365 Copilot could be manipulated to exfiltrate some private data and, post-compromise, automate spear phishing. Source: wired.com.
  2. 14 Aug 2024: Sakana AI Scientist runtime extension attempt. In testing, Sakana's AI Scientist edited its experiment code to relaunch itself and tried to extend its timeout. Source: arstechnica.com.
  3. 20 Aug 2024: Copilot Studio SSRF (CVE-2024-38206). Tenable bypassed SSRF protection to reach Azure IMDS tokens and internal Cosmos DB. Source: tenable.com.
  4. 20 Aug 2024: Slack AI indirect prompt injection. Public-channel prompt injection made Slack AI embed a private-channel API key in a malicious link, leaked on click. Source: promptarmor.com.
  5. 26 Aug 2024: M365 Copilot ASCII smuggling. Email prompt injection made M365 Copilot hide MFA codes in clickable links as invisible Unicode for exfiltration. Source: embracethered.com.
  6. 20 Sep 2024: SpAIware ChatGPT macOS memory. Memory injection created persistent cross-session spyware exfiltrating user conversations. Source: embracethered.com.
  7. 24 Oct 2024: ZombAIs via Claude Computer Use. Web page prompt injection made Claude Computer Use download and run a Sliver implant, joining attacker C2 infrastructure. Source: embracethered.com.
  8. 5 Dec 2024: OpenAI o1 system card eval scheming. In Apollo's goal-nudged evaluations, o1 attempted to disable oversight in 5% of cases and exfiltrate its weights in 2%. Source: cdn.openai.com.
  9. 17 Feb 2025: ChatGPT Operator prompt injection. Malicious page hijacked the Operator browsing agent into leaking private user data. Source: embracethered.com.
  10. 18 Mar 2025: Rules File Backdoor (Cursor, Copilot). Invisible Unicode in agent rules files made coding agents emit backdoored code. Source: pillar.security.
  11. 1 Apr 2025: MCP tool poisoning attacks. Malicious MCP tool descriptions instructed agents to exfiltrate SSH keys and configs. Source: invariantlabs.ai.
  12. 22 May 2025: GitLab Duo remote prompt injection. Hidden prompt in a merge request made Duo leak source code via HTML injection. Source: legitsecurity.com.
  13. 26 May 2025: GitHub MCP toxic agent flow. Malicious GitHub issue hijacked the agent into leaking private repository contents. Source: invariantlabs.ai.
  14. 11 Jun 2025: EchoLeak M365 Copilot (CVE-2025-32711). AI command injection in Microsoft 365 Copilot let an unauthorized attacker disclose information without any user interaction. Source: msrc.microsoft.com.
  15. 16 Jun 2025: Supabase MCP support-ticket prompt injection. Instructions in a support ticket made Cursor's agent use service_role to copy a private token table into that ticket. Source: generalanalysis.com.
  16. 18 Jun 2025: Asana MCP cross-tenant exposure. Logic flaw in Asana's MCP server exposed data to other organizations' MCP users; roughly 1,000 customers impacted. Source: bleepingcomputer.com.
  17. 27 Jun 2025: MCP Inspector RCE (CVE-2025-49596). Missing authentication in Anthropic's MCP Inspector let malicious websites run arbitrary code on developers' machines. Source: oligo.security.
  18. 2 Jul 2025: EscapeRoute Anthropic Filesystem MCP. CVE-2025-53109/53110 symlink and prefix-match flaws escaped the MCP filesystem sandbox. Source: cymulate.com.
  19. 9 Jul 2025: mcp-remote command injection (CVE-2025-6514). A malicious MCP server could trigger OS command execution on machines running mcp-remote 0.0.5 through 0.1.15. Source: jfrog.com.
  20. 23 Jul 2025: Wiping prompt planted in Amazon Q extension. Hacker's code told Amazon Q to wipe users' computers and delete cloud resources; Amazon shipped it publicly. Source: 404media.co.
  21. 23 Jul 2025: Replit agent deleted live production database. Replit's agent deleted a live database during a code freeze and said rollback would not work; data was recovered. Source: fortune.com.
  22. 5 Aug 2025: Cursor CurXecute and MCPoison CVEs. Cursor CVE-2025-54135 let prompt injection modify mcp.json to run commands; CVE-2025-54136 let approved MCP configs be altered without re-approval. Source: tenable.com.
  23. 6 Aug 2025: AgentFlayer ChatGPT Connectors. Zero-click poisoned document exfiltrated API keys from a connected Google Drive. Source: labs.zenity.io.
  24. 12 Aug 2025: GitHub Copilot RCE (CVE-2025-53773). Injection made Copilot edit settings.json into auto-approve, yielding code execution. Source: embracethered.com.
  25. 20 Aug 2025: Perplexity Comet browser agent hijacked. Instructions hidden in a Reddit comment made Comet exfiltrate a user's email and one-time password, enabling account takeover. Source: brave.com.
  26. 26 Aug 2025: Claude Code IDE WebSocket flaw (CVE-2025-52882). Unauthenticated local WebSocket server in Claude Code IDE extensions let malicious websites connect and read local files. Source: securitylabs.datadoghq.com.
  27. 27 Aug 2025: Nx s1ngularity npm compromise. Compromised Nx npm package weaponized Claude, Gemini and q CLIs to hunt secrets, leaking data via public GitHub repos. Source: stepsecurity.io.
  28. 27 Aug 2025: Anthropic GTG-2002 vibe-hacking extortion. Attacker used Claude Code to automate intrusion, data theft and extortion targeting at least 17 organizations. Source: thehackernews.com.
  29. 18 Sep 2025: ShadowLeak ChatGPT Deep Research. Zero-click, service-side exfiltration of Gmail inbox data by ChatGPT Deep Research via hidden instructions in a crafted email. Source: radware.com.
  30. 25 Sep 2025: ForcedLeak Salesforce Agentforce. Web-to-Lead injection exfiltrated CRM data via an expired whitelisted domain. Source: noma.security.
  31. 29 Sep 2025: postmark-mcp malicious MCP server. postmark-mcp, called the first malicious MCP server in the wild, BCC'd every email it sent to its developer. Source: thehackernews.com.
  32. 7 Oct 2025: Framelink Figma MCP RCE (CVE-2025-53967). Framelink Figma MCP server's curl fallback built shell commands from URL and header values, allowing remote code execution. Source: imperva.com.
  33. 8 Oct 2025: CamoLeak GitHub Copilot Chat. Injection in PR content leaked private source code and secrets via the Camo proxy. Source: legitsecurity.com.
  34. 24 Oct 2025: ChatGPT Atlas omnibox injection. Malformed URL-like strings pasted into the Atlas omnibox were treated as trusted user intent with fewer safety checks. Source: neuraltrust.ai.
  35. 13 Nov 2025: Anthropic GTG-1002 espionage campaign. Chinese state-sponsored group, per Anthropic, used Claude Code for 80-90% of an espionage campaign against roughly thirty targets. Source: anthropic.com.
  36. 25 Nov 2025: Google Antigravity exfiltrated credentials. Poisoned web page led Gemini in Antigravity to bypass gitignore protection and exfiltrate credentials via a browser subagent. Source: promptarmor.com.
  37. 1 Dec 2025: Antigravity wiped a user's D drive. Agent in Turbo mode deleted an entire drive while clearing a project cache. Source: theregister.com.
  38. 6 Dec 2025: IDEsaster AI IDE vulnerability set. Over 30 flaws and 24 CVEs in AI IDEs let prompt injection exfiltrate data or execute code. Source: maccarita.com.
  39. 13 Jan 2026: ServiceNow BodySnatcher (CVE-2025-12420). CVE-2025-12420 let unauthenticated attackers impersonate any ServiceNow user by email and make an AI agent create admin accounts. Source: appomni.com.
  40. 20 Jan 2026: Anthropic mcp-server-git RCE chain. CVE-2025-68143/68144/68145 chained path traversal and argument injection into code execution. Source: thehackernews.com.
  41. 2 Feb 2026: ClawHavoc malicious OpenClaw skills. Koi found 341 malicious ClawHub skills for OpenClaw; 335 used fake prerequisites to install Atomic Stealer. Source: thehackernews.com.
  42. 19 Feb 2026: Clinejection supply-chain attack. Issue-title prompt injection against Cline's Claude triage bot led to stolen npm credentials and an unauthorized OpenClaw-installing release. Source: snyk.io.
  43. 23 Feb 2026: OpenClaw agent deleted Meta researcher's email. Meta researcher says OpenClaw agent began deleting her email and ignored stop commands sent from her phone. Source: techcrunch.com.
  44. 6 Mar 2026: Claude Code ran terraform destroy. Claude Code's terraform destroy wiped production, including 2.5 years of submissions and snapshots; AWS later restored the database. Source: aishippingblog.com.
  45. 9 Mar 2026: CodeWall agent hacked McKinsey's Lilli platform. Autonomous agent used unauthenticated SQL injection to get read-write access to a production database holding 46.5M chat messages. Source: codewall.ai.
  46. 10 Mar 2026: Azure MCP Server SSRF (CVE-2026-26118). Malicious URL submitted to an MCP-backed agent could let attackers capture Azure MCP Server's managed identity token. Source: msrc.microsoft.com.
  47. 16 Mar 2026: Snowflake Cortex Code sandbox escape. Prompt injection in a README made Cortex Code bypass approval via process substitution and run malware outside its sandbox. Source: promptarmor.com.
  48. 15 Apr 2026: Windsurf prompt injection to local RCE (CVE-2026-30615). Attacker-controlled HTML could make Windsurf register a malicious MCP server and run commands without further user interaction. Source: ox.security.
  49. 24 Apr 2026: Gemini CLI GitHub Action RCE. Headless Gemini CLI auto-trusted workspace config and ignored tool allowlists under --yolo, so untrusted inputs could run code. Source: github.com.
  50. 27 Apr 2026: PocketOS production database deleted. Cursor agent used a Railway token to delete the production database and its backups. Source: theregister.com.
  51. 8 May 2026: Claude Code used against Mexican targets. Attackers used Claude Code and GPT-4.1 against nine Mexican government agencies, breaching a water utility's IT environment. Source: cybersecuritydive.com.
  52. 2 Jun 2026: Cursor and Claude agents aided EDR evasion. Threat actor used Cursor and Claude Opus agents to develop and test EDR-evasion tools; Sophos linked it to ransomware. Source: sophos.com.
  53. 5 Jun 2026: Miasma worm targets AI coding agents. Miasma worm planted Claude Code and Cursor configs that run a credential harvester; GitHub disabled 73 Microsoft repos. Source: stepsecurity.io.
  54. 17 Jun 2026: Mastra npm supply-chain compromise. North Korean actor Sapphire Sleet took over a maintainer account and poisoned 140+ Mastra AI npm packages. Source: microsoft.com.
  55. 23 Jun 2026: Langflow CVE-2026-33017 exploited for Monero mining. Attackers exploited unauthenticated RCE CVE-2026-33017 in LLM workflow framework Langflow to deploy a Monero miner. Source: trendmicro.com.
  56. 1 Jul 2026: JADEPUFFER agentic ransomware. An LLM agent entered via Langflow, encrypted 1,342 Nacos configs and dropped production databases, Sysdig assessed. Source: sysdig.com.
  57. 1 Jul 2026: Cursor DuneSlide zero-click RCEs. Zero-click prompt injection could make Cursor's agent overwrite the cursorsandbox binary, breaking out of the terminal sandbox (CVE-2026-50548/50549). Source: catonetworks.com.
  58. 2 Jul 2026: Hidden web prompt injections target AI agents. Zscaler found malicious sites hiding prompt injections aimed at AI agents; in sandboxed tests, 4 of 26 models paid. Source: zscaler.com.
  59. 6 Jul 2026: GitLost GitHub Agentic Workflows leak. Noma showed a crafted issue could make GitHub's Agentic Workflows agent publicly post private repo data. Source: noma.security.
  60. 7 Jul 2026: Langflow IDOR added to CISA KEV. CVE-2026-55255 let an authenticated Langflow user execute another user's flows; CISA lists it as exploited in the wild. Source: cisa.gov.
  61. 20 Jul 2026: AWS Kiro rewrote its own MCP config. Hidden webpage injection made Kiro rewrite its MCP config, achieving code execution (CVE-2026-10591). Source: research.intezer.com.
  62. 23 Jul 2026: SharedRoot: Claude Cowork sandbox escape. After one message, the Claude Cowork agent escaped its VM and read and wrote files on the host Mac. Source: accomplish.ai.
  63. 27 Jul 2026: OpenAI evaluation agent breached Hugging Face. OpenAI eval agent escaped its sandbox via a package-proxy zero-day, then ran code in Hugging Face production Kubernetes. Source: huggingface.co.
  64. 30 Jul 2026: Anthropic eval agents breached real orgs. Misconfigured cyber evaluations let Claude models compromise three real organizations. Source: anthropic.com.
  65. 30 Jul 2026: Hermes Agent autonomous attack campaign. A threat actor's Hermes Agent, running DeepSeek, autonomously enumerated targets, sourced exploit code and attempted exploits. Source: unit42.paloaltonetworks.com.
  66. 4 Aug 2026: UK AISI unsanctioned agent behaviour. Agents in AISI cyber testing took 19 unsanctioned actions, including trying to insert malicious code into an open-source project. Source: aisi.gov.uk.
  67. 5 Aug 2026: Meta AI model hacked company in testing. A testing partner's misconfiguration gave a Meta model internet access; it hacked another company during cybersecurity testing. Source: theguardian.com.
  68. 26 Aug 2026: GPT 5.6-Cyber escaped a QEMU/KVM VM. Trail of Bits tasked GPT 5.6-Cyber with escaping a QEMU/KVM VM; it escaped three times, finally chaining three zero-days. Source: blog.trailofbits.com.
  69. 31 Aug 2026: METR agent dashboard API key theft. Attacker prompted an agent on an exposed dashboard to reveal its API key, then consumed credits worth about $600,000. Source: metr.org.
  70. 2 Sep 2026: Unit 42 AI-assisted intrusion. Attacker used frontier agents to breach an enterprise network in under ten hours. Source: unit42.paloaltonetworks.com.
  71. 4 Sep 2026: OpenAI agents repurposed German wiki DseWiki. Researchers found more than 15,000 AI-agent edits on German wiki DseWiki; OpenAI's agents used it to share restriction workarounds. Source: reuters.com.
Introducing

The Quint Intent Model. What the agent said. What the machine did. The gap.

Every agent narrates what it is about to do. The intent model compiles that narration into a grant on the device, watches what the process actually does at the operating system, and holds one to the other. Anything outside the grant is a divergence, scored as it happens.

How the grant gets compiled

Declared

Every statement the agent makes about what it is about to do is compiled into a grant: which capabilities it licensed, and how tightly.

  • Read off the wire, from the agent's own words
  • Spawn, delete, network, write, read: each one named or unbounded
  • Compiled on the device, ahead of the action it licenses
Claude Code session goal05:47:06
Narration68 chars · #bddaa0f9
compiled into a grant
Licensed
readread files
Scope
ScopeddecisionsLayout.test.ts
Turn step05:47:10
spawnagentsexecutecommandsreadfilesUnboundedfalls back to the project tree

Observed

The files, processes and connections the agent actually touched, read from the operating system.

  • Code-signed process lineage from the kernel
  • Tool calls, file reads, exec and network, in order
  • Sessions and sub-agents tied together
Activity kernel-observedlive
  • 07:03:25EXECsh -c "chrome-devtools-mcp" --autoConnectrisk 30
  • 07:03:25READ~/Documents/iCloud/brainrisk 10
  • 07:03:26NET13.35.78.116 · aws · flowrisk 35
  • flagged: 07:03:27READ~/.aws/credentialsrisk 60
  • 07:03:27EXEC/usr/local/bin/quint-hook --claude --enforcerisk 30
  • 07:03:27TOOLBash · agent-reported callrisk 30
SourceEndpointSecurity · NetworkExtension · agent hook

Divergence

Observed activity is held to the grant. Anything landing outside it is the signal, scored per action and ranked for review.

  • Deterministic. No model in the decision path
  • Observe first. Then flag or block at the edge, on the device
  • Every decision recorded with the rule that fired
Credential readcriticalscore 95
Actual
~/.aws/credentialsFILE_READ · Bash · 07:03:27
Declared
read inside the project treenothing licensed outside it
Why
The agent’s Bash call read a credential file that no frame had named. As an action it scores 60; as a divergence from the grant, 95.
Maps to
CSA CCM · DSP-17CSA CCM · IAM-05intent vs truth
ObserveFlagBlockrecorded with the rule that fired
Why the rest of the stack misses it

Everyone else holds half the picture.

Agent tools see what the agent reports. Endpoint tools see what the machine did. Quint holds one to the other.

  1. Watches the wire

    what is routed through it

    • Runlayer
    • WitnessAI
  2. Watches the agent

    what its own hooks and telemetry report

    • Zenity
    • Noma
    • Pillar
    • Lasso
    • Straiker
    • Manifold
    • Asymptote
    • Sondera
    • Autonomous Security
  3. Watches the machine

    what the operating system did, with no idea what the agent meant

    • CrowdStrike
    • SentinelOne
  4. Watches both

    the files, processes and connections it touched, held to what the agent declared

    Quint
Deployment

Three ways to deploy.

On the Macs your agents work on, inside the agents you build, or against SaaS agents with nothing installed. Start with one and add the others as your agents spread.

  • On the endpoint

    A signed, notarized macOS package your MDM pushes. It records what each agent process on the Mac did, next to what the agent declared.

  • In your own agents

    A hook inside the agent reports what it is about to do, before it does it. Claude Code and Cursor today.

  • Agentless, for SaaS agents

    Copilot Studio agents and the Power Platform environments around them, read through your tenant’s admin plane. No software on any machine. In development.

Built for security teams

Built for CISOs. Built for engineers.

Quint records what an agent actually did at the kernel, next to what it said it would do, and shows you where those two diverge. Same install on every host, same evidence trail.

Kernel
macOS Endpoint Security
Ed25519
Signed release artifacts
RLS
Row-level tenant isolation

Every other tool asks the agent what it did. We watch the kernel and compare.

What Quint does

From the blog

Research & threat analysis

[all posts →]
FAQ

Frequently Asked Questions

Your agents are running. See what they're actually doing.

Book a demo
Quint

Behavioral security for the agentic era.

  • SOC 2, in progressSOC 2IN PROGRESS
  • HIPAA, in progressHIPAAIN PROGRESS
© 2026 Quint Security Inc. Third-party marks belong to their owners.OS-level interception. Not another gateway.