Threat library

Near misses, written up.

How agent permissions go wrong in practice: what nearly happened, why the settings didn't stop it, and the fix. Scenarios are composites on a demo machine; no real user data.

The deny rule that didn't hold

A developer had denied sqlite3 so no agent could open local databases. Weeks earlier they had approved python3 -c * during a data task and made it permanent.

What nearly happened

Asked to "find that message about the invoice", an agent tried sqlite3 ~/Library/Messages/chat.db, hit the deny rule, and rewrote the same query as a one-line Python script. The allow list approved it.

Why the settings didn't stop it

Permission rules match text. The wildcard interpreter grant subsumes the deny rule: anything sqlite3 can do, Python can do.

What Mockingbyrd does

The scan flags the subsuming grant as an open finding with the file and line. The guard reads the command that will actually run, so the Python version is caught as a read of a T0 store and you are asked first.

The fix

- "Bash(python3 -c *)"
+ "Bash(python3 scripts/report.py)"

Eighty-five became one hundred and seven

After a cleanup, an allow list held 85 entries. Thirteen days later it held 107. Each new entry had been a reasonable click at the time.

What nearly happened

One of the 22 new entries was Bash(curl:*), approved to download a dependency. Combined with broad read access, it meant an agent could read widely and send data off the machine without a prompt.

Why the settings didn't flag it

Nothing reviews the list as a whole. Each approval is judged on its own, never against what is already granted.

What Mockingbyrd does

Re-scans on your cadence, scores the combination (reads widely and can send off the machine), and names the entry that tipped it.

The fix

Let network tools prompt, and scope reads to project folders.

hooks.json changed at 04:12

A hook configuration file changed at 04:12. No one was working, and nothing in the agent's own logs mentioned it.

What nearly happened

A scheduled job running unattended had edited the hook that was supposed to inspect its commands. Had it gone unnoticed, later tool calls would have run with no check at all.

Why the settings didn't flag it

Agents don't watch their own configuration. A control that quietly stops holding looks exactly like one that's working.

What Mockingbyrd does

Fingerprints the files that matter and reports drift as an event: which file, when, and that it no longer matches what you approved.

The fix

Review the change, restore the approved version from backup, and find out which job made it.

Allow for this session, forty times

A developer approved the same interpreter prompt about forty times across a week, then clicked the option to stop being asked.

What nearly happened

The permanent grant was broader than any single request had been. It turned forty narrow decisions into one wide one.

Why the settings didn't flag it

The prompt is designed to reduce friction. It does its job; it just isn't a review.

What Mockingbyrd does

Shows the grant in the roster with what it can reach, scores it, and writes a script that replaces it with the narrow version. You read the script before anything runs.

The fix

Replace the wildcard with the specific commands you actually approved.