cursor-agent-v0.4.2
sarah.chen·Engineering·2h ago
Approve Installation ⏱ 2h pending

cursor-agent-v0.4.2 is an AI coding assistant sub-process. Detected reads of ~/.aws/credentials and ~/.ssh/id_rsa via MCP tool calls — a known AI agent prompt injection pattern where agents are manipulated to exfiltrate credentials. Publisher cert is valid but agent runs with dev's full permissions. 47 engineers have requested this tool in 30 days.

PublisherUnverified
Credential access~/.aws/credentials, ~/.ssh/id_rsa
Prompt injection riskDetected via MCP tool calls
Endpoints affected47 engineers
Background processRuns with full dev permissions
82%
AI recommends: Approve with restrictions

Override AI recommendation? AI suggested "Approve with restrictions". Confirm full Approve?

Confirm restriction of cursor-agent-v0.4.2? This will block installation for all pending requesters.

Notify team owner? An automated message will be sent to sarah.chen requesting justification.

npm: lightllm 0.2.1
alex.kim·Engineering·5h ago
Allow Network Access ⏱ 5h · Auto-block in 19h

npm package lightllm v0.2.1 has been flagged for supply chain indicators. Telemetry recorded outbound connections to 185.220.101.47 — a known Tor exit node. The package was published 8 days ago with no prior version history. Three other packages by the same author were pulled from npm last month.

PublisherUnknown / unverified
C2 connection185.220.101.47 (Tor exit node)
Package age8 days · no prior history
Author history3 prior packages removed from npm
97%
AI recommends: Restrict
AI confidence is 97% for restricting this package. Proceeding will be logged and flagged to the CISO dashboard.

Confirm restriction of npm: lightllm 0.2.1? The package will be blocked fleet-wide immediately.

Notifying the team owner of a Critical risk delays automatic blocking. This will be noted in the audit log.
Proxyman 4.7
carlos.torres·Design·1d ago
Approve Installation ⏱ 1d · SLA expires soon

Proxyman is a well-known macOS HTTP proxy/debug tool used by developers. Signed by Proxyman OÜ with valid Apple developer certificate. The app intercepts HTTPS traffic by design, which grants it access to decrypted credentials in transit. Use should be limited to dev environments.

PublisherSigned · Proxyman OÜ
CVEsNone
HTTPS interceptDecrypts all HTTPS traffic
Scope concernShould be dev-only
71%
AI recommends: Approve (dev machines only)

Approve Proxyman 4.7 for installation? Access will be scoped to dev machines in policy.

Confirm restriction of Proxyman 4.7? This overrides the AI recommendation. carlos.torres will be notified.

Notify team owner? carlos.torres will be asked to confirm the business need and target environment.

Wireshark 4.2
maya.johnson·Security·via Slack #security-tools·3s ago
Exception Request ⚡ Just now
Developer Self-Service Request

"I need Wireshark to capture traffic for a pentest engagement on our staging network. This is for the Q2 internal red team exercise (JIRA: SEC-1847). ~30 min session on my isolated test machine."

JIRA: SEC-1847 Duration: 30 min · one-time Scope: 1 endpoint (isolated)

Wireshark is a legitimate network analyzer signed by the Wireshark Foundation. No supply chain indicators. Request cites verifiable JIRA ticket SEC-1847. maya.johnson is in the Security team with prior approved tool exceptions. The 30-min scoped exception pattern is consistent with internal pentest protocols.

PublisherWireshark Foundation
JIRA ticketSEC-1847 · verifiable
Requester historySecurity team · prior exceptions approved
Network captureFull traffic intercept capability
91%
AI recommends: Approve · scoped exception

Grant 30-minute exception for Wireshark 4.2 on maya.johnson's machine? ShieldOps will auto-revoke at expiry and log all captures.

Deny exception for Wireshark 4.2? maya.johnson will be notified with the reason.

Request additional info from maya.johnson? They will be prompted to confirm the target environment and data flows.

Recent Decisions 8 entries
AI Approved High-confidence · auto-resolved
3
Requires Human Review Low confidence or elevated risk
2
VSCode AWS Toolkit Approved
james.park · 3h ago AI: 68%
Homebrew 4.2.1 Approved
system · 4h ago AI: auto
MacUpdater 3.0 Restricted
jamie.r · 6h ago AI: 79%
unknown-binary-c Restricted
AI auto · 9h ago AI: 96%
unknown-binary-b Restricted
AI auto · 12h ago AI: 94%
pyenv 2.3.35 Approved
j.rodriguez · 1d ago AI: 61%
node-gyp-unofficial Restricted
AI auto · 2d ago AI: 88%
Docker Desktop 4.28 Approved
james.park · 3d ago AI: 72%