All tutorials

Every AI agent and MCP location

Cordon 0.6.08 sections · 0 diagramsView this tutorial on GitHub

Everything a repository can hand a coding agent, the exact paths Cordon reads for each, and every rule that judges them. Rendered from the detector itself, so a location added to the code appears here, and one that is not read never does. The walkthrough is tutorial 18.

   instruction files ──┐   skills, commands ───┤   settings and hooks ─┼──►  read, never run  ──►  Cordon's agent rules   MCP configurations ─┤                           Agent Threat Rules   files run on open ──┤                           intent, offline   CI agent actions ───┘                           the judge, if asked

Text an agent reads as its instructions. Checked for hidden characters, injection wording, remote instructions, what the text asks for, and the Agent Threat Rules.

PathRead by
CLAUDE.mdClaude Code
CLAUDE.local.mdClaude Code
AGENTS.mdCodex, Amp and AGENTS.md readers
AGENT.mdCodex, Amp and AGENTS.md readers
GEMINI.mdGemini CLI
.cursorrulesCursor
.cursor/rules/**Cursor
.windsurfrulesWindsurf
.windsurf/rules/**Windsurf
.clinerulesCline
.clinerules/**Cline
.github/copilot-instructions.mdGitHub Copilot
.github/instructions/**GitHub Copilot
.github/prompts/**GitHub Copilot
SKILL.mdClaude Code and other skill readers
.claude/commands/**Claude Code
.claude/agents/**Claude Code
.claude/skills/**Claude Code
.claude/output-styles/**Claude Code
.github/chatmodes/**GitHub Copilot
.github/agents/**GitHub Copilot
.cursor/commands/**Cursor
.gemini/commands/**Gemini CLI
.opencode/agent/**opencode
.opencode/command/**opencode
.windsurf/workflows/**Windsurf
.kiro/steering/**Kiro
.amazonq/rules/**Amazon Q
.junie/**JetBrains Junie
.augment-guidelinesAugment
.augment/rules/**Augment
.trae/rules/**Trae
.roo/rules/**Roo Code
.roo/rules-*/**Roo Code
.continue/rules/**Continue
.continue/prompts/**Continue
.rulesZed
.goosehintsgoose

Configuration that decides what an agent may do, and hooks it runs on its own: permissions granted, commands run on events, approval switched off.

PathRead by
.claude/settings.jsonClaude Code
.claude/settings.local.jsonClaude Code
managed-settings.jsonClaude Code (managed)
hooks/hooks.jsonClaude Code plugins
.cursor/hooks.jsonCursor
.windsurf/hooks.jsonWindsurf
.gemini/settings.jsonGemini CLI
.kiro/hooks/*Kiro
.codex/config.tomlCodex

Every MCP configuration dialect. Each local server is resolved to the exact package it launches and read from the registry tarball; each remote one, with --online, is asked what it serves now (tutorial 18).

PathRead by
.mcp.jsonevery MCP client that reads a project file
.cursor/mcp.jsonCursor
.vscode/mcp.jsonVS Code
.gemini/settings.jsonGemini CLI
.windsurf/mcp.jsonWindsurf
.roo/mcp.jsonRoo Code
claude_desktop_config.jsonClaude Code
mcp.jsonMCP clients
cline_mcp_settings.jsonCline
.zed/settings.jsonZed
opencode.jsonopencode
opencode.jsoncopencode
.codex/config.tomlCodex
.continue/config.yamlContinue
.continue/mcpServers/*Continue

Commands an editor or agent runs without anyone typing them: tasks set to run on open, dev-container lifecycle commands, background-agent setup.

PathRead by
.vscode/tasks.jsonVS Code
.devcontainer/devcontainer.jsonDev Containers
.devcontainer.jsonDev Containers
.devcontainer/*/devcontainer.jsonDev Containers
.cursor/environment.jsonCursor

Extensions and plugins a repository asks to have installed, checked against the marketplaces' own malware and impersonation verdicts.

PathRead by
.vscode/extensions.jsonVS Code
.devcontainer.jsonDev Containers
.devcontainer/devcontainer.jsonDev Containers
.devcontainer/*/devcontainer.jsonDev Containers
*.code-workspaceVS Code
.gitpod.ymlGitpod
.gitpod.yamlGitpod
BrewfileHomebrew, into VS Code
.claude-plugin/marketplace.jsonClaude Code

Workflow steps that run a coding agent, checked for untrusted triggers, write permissions and broad tools.

ActionAgent
anthropics/claude-code-actionClaude Code
anthropics/claude-code-base-actionClaude Code
google-github-actions/run-gemini-cliGemini CLI
openai/codex-actionCodex

cordon-scanner agent inventory reads these, and only these; agent report sends the list, never a file's contents. Paths shown for Linux; on macOS and Windows the application-support folder is used.

PathToolKind
~/.claude/settings.jsonclaude-codesettings
~/.claude/settings.local.jsonclaude-codesettings
~/.claude/CLAUDE.mdclaude-codeinstructions
~/.claude.jsonclaude-codeclaude-json
~/.config/Claude/claude_desktop_config.jsonclaude-desktopmcp
~/.cursor/mcp.jsoncursormcp
~/.codeium/windsurf/mcp_config.jsonwindsurfmcp
~/.gemini/settings.jsongemini-climcp
~/.gemini/GEMINI.mdgemini-cliinstructions
~/.config/Code/User/settings.jsonvscodesettings
~/.config/Code/User/mcp.jsonvscodemcp
~/.codex/config.tomlcodexcodex-toml
~/.codex/AGENTS.mdcodexinstructions
~/.npmrcnpmnpmrc
~/.config/pip/pip.confpippip
~/.pip/pip.confpippip

46 rules of Cordon's own, beside the Agent Threat Rules (tutorial 28 lists those too).

RuleSeverityWhat it catches
MALWARE.AGENT.AUTORUN.001criticalA command an editor or agent runs on its own attacks the machine
MALWARE.AGENT.HOOK_EXFIL.001criticalAn agent hook that sends credentials away or opens a remote shell
MALWARE.AGENT.HOOK_FETCH_EXEC.001criticalAn agent hook that fetches and executes remote code
MALWARE.EXTENSION.KNOWN.001criticalAn editor extension is a recorded malicious release
MALWARE.EXTENSION.REMOVED.001criticalA recommended or vendored editor extension was removed from the Marketplace as malware
OPERATIONAL.MCP.UNRESOLVEDinfoAn MCP server package was not examined
POLICY.AGENT.AUTO_APPROVE.001highAgent confirmations switched off in committed settings
POLICY.AGENT.MCP_BROAD_SCOPE.001mediumA filesystem MCP server given the whole disk or home directory
POLICY.AGENT.WIDE_DIRECTORY.001mediumAgent given the whole disk or home directory to work in
POLICY.AGENT.WILDCARD_PERMISSION.001mediumAgent permissions allow any shell command
SECRET.MCP.INLINE_CREDENTIAL.001highA credential written inline in an MCP configuration
SUSPECT.AGENT.API_REDIRECT.001highAgent API traffic redirected to a host that is not the provider
SUSPECT.AGENT.ATR.AGENT_MANIPULATION.001mediumText that impersonates an agent or hijacks the agent's task
SUSPECT.AGENT.ATR.CONTEXT_EXFILTRATION.001mediumText that asks an agent to move secrets or context off the machine
SUSPECT.AGENT.ATR.DATA_POISONING.001mediumText that plants triggers or false facts for an agent
SUSPECT.AGENT.ATR.EXCESSIVE_AUTONOMY.001mediumText that asks an agent to act without the user's confirmation
SUSPECT.AGENT.ATR.MODEL_ABUSE.001mediumText that turns an agent toward abuse of the model
SUSPECT.AGENT.ATR.MODEL_SECURITY.001mediumText that targets the model's weights or safety
SUSPECT.AGENT.ATR.PRIVILEGE_ESCALATION.001mediumText that asks an agent to widen its own permissions
SUSPECT.AGENT.ATR.PROMPT_INJECTION.001mediumText that tries to override an agent's instructions
SUSPECT.AGENT.ATR.SKILL_COMPROMISE.001mediumA skill or plugin shaped like a known compromise
SUSPECT.AGENT.ATR.TOOL_POISONING.001mediumText that turns a tool into a channel for steering the agent
SUSPECT.AGENT.CI_PROMPT_INJECTION.001highUntrusted event text passed straight into an agent's prompt
SUSPECT.AGENT.CI_UNTRUSTED_TRIGGER.001highAn AI agent in CI reads text an outsider can write
SUSPECT.AGENT.CREDENTIAL_EXFIL.001criticalAgent instructions that move credentials somewhere
SUSPECT.AGENT.FETCH_EXEC.001highAgent instructions that fetch and execute remote code
SUSPECT.AGENT.HIDDEN_TEXT.001highHidden characters in an agent instruction file
SUSPECT.AGENT.HOOK.001mediumAn agent hook committed to the repository
SUSPECT.AGENT.INJECTION_TEXT.001mediumInstruction-like text aimed at a coding agent
SUSPECT.AGENT.INTENT.001highText that tells the agent to act against its user
SUSPECT.AGENT.INTENT_CHAINED.001highAgent instructions that send the agent to a file that acts against its user
SUSPECT.AGENT.PLUGIN_SOURCE.001highAgent plugins installed from an unverified source
SUSPECT.AGENT.REMOTE_INSTRUCTIONS.001mediumAn agent instruction file tells the agent to fetch and follow remote text
SUSPECT.AGENT.SENSITIVE_IMPORT.001highAn agent instruction file imports a credential file
SUSPECT.EXTENSION.LOOKALIKE.001mediumA recommended editor extension imitates a popular one
SUSPECT.EXTENSION.MALICIOUS_VERSIONS.001lowA named editor extension has had malicious releases
SUSPECT.EXTENSION.REMOVED.001highA recommended or vendored editor extension was removed from the Marketplace
SUSPECT.MCP.CONTAINER_HOST_ACCESS.001highAn MCP server's container is given the host
SUSPECT.MCP.ENV_INJECTION.001highAn MCP server's environment loads code into it before it starts
SUSPECT.MCP.INSECURE_TRANSPORT.001highA remote MCP server over plain HTTP
SUSPECT.MCP.LOOKALIKE.001highAn MCP server package named like a popular one
SUSPECT.MCP.SHELL_LAUNCH.001highAn MCP server launched through a shell that fetches code
SUSPECT.MCP.TOOL_DESCRIPTION.001highA tool in this repository's MCP server instructs the agent
SUSPECT.MCP.UNPINNED.001mediumAn MCP server launched from an unpinned package
SUSPECT.MCP.UNTRUSTED_REMOTE.001highA remote MCP server on a tunnel, paste or interaction host
VULNERABLE.AGENT.ACTION_VERSION.001highAn AI agent action below its security fix

Agent Threat Rules findings are reported in these categories: agent-manipulation, context-exfiltration, data-poisoning, excessive-autonomy, model-abuse, model-security, privilege-escalation, prompt-injection, skill-compromise, tool-poisoning.

Next: 28 · Every rule.