Blog

Hooks, Rules Files and Connectors: The Vetting Blind Spot on Every Endpoint

At a glance

  • Hooks, rules files and connectors carry standing instructions nobody reviewed, and they never show up in MDM inventories or process-level endpoint telemetry.
  • Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint.
  • Backslash Security blocks risky agent actions inline before execution, including unauthorized code execution, credential access, privilege escalation, and data sent to unapproved destinations.
  • Latio's 2026 AI Security Market Report named Backslash Security an Endpoint AI Security Leader for in-depth AI controls on the endpoint.

Backslash Security

Published:

Among the components that can turn an approved AI agent against its own operator, the ones security teams rarely review are hooks, rules files and connectors. A hook is a trigger that fires on an agent action, running something before or after it. A rules file — AGENTS.md or CLAUDE.md — is a file in a repository or on a machine that carries standing instructions an agent reads on every run. A connector is the wiring that lets an agent reach an external system under the employee's own identity and access. None of these installs like software, so none of them lands in a device management inventory in Intune or Jamf, and none of them registers with endpoint detection and response, which is built to catch malicious processes, files and known-bad behavior on a machine. This is not shadow AI in the usual sense, either: the agent itself may be fully sanctioned, while the instructions steering it were never seen. The vetting gap here is structural — approval workflows attach to things that get installed, so plain text an agent reads at runtime inherits that agent's standing permissions without ever passing through review. As of 2026, the exposure is documented: Backslash Security research found that malicious instructions hidden in a repository's AGENTS.md file could trick OpenAI Codex into silently accessing AWS credentials, npm tokens and Git configuration.

What exactly are hooks, rules files, and connectors in an agentic AI setup?

Hooks, rules files, and connectors are discrete artifacts on an employee's machine that change how an AI agent behaves—each modifying something different. Approving the agent itself does not approve the instructions, triggers, and integrations attached afterward.

Artifact What it is What it changes Why it matters on an endpoint
Agent Skills Packaged instructions and scripts that extend what an agent can do — often just a markdown file on the machine Capability: a Skill can tell an agent to read a file, call an API, or run a shell command Executes with the user's own permissions; rarely reviewed like code
MCP server A service reachable over the Model Context Protocol, which agents use to connect to external tools and data Reach: each server is a live connection an agent can act through Adds an outbound path to systems the agent was never scoped for
MCP tool An individual callable function exposed by an MCP server The specific action available, not the connection itself Server-level approval does not imply tool-level approval
Hook A trigger that fires on an agent action, running something before or after it Execution flow around the agent's own steps Runs automatically, with no prompt and no human in the loop
Rules file (AGENTS.md, CLAUDE.md) A file in a repository or on a machine carrying standing instructions the agent reads on every run Standing intent: what the agent believes it was told to do Read silently each run, and editable by anyone with repository write access
Plugin / connector Installed extensions and configured links into third-party services Available integrations and credentials in play Often bound to a personal account rather than a corporate identity

Backslash Security calls this interconnected layer the agentic AI fabric, because these artifacts combine at runtime inside tools such as Claude Code and Cursor rather than acting one at a time.

Why do these artifacts slip past standard vetting processes?

When an approval process stops at the application, hooks, rules files and connectors slip past as configuration artifacts rather than software. A hook triggers on agent actions, running code before or after. A rules file—AGENTS.md or CLAUDE.md in a repository or home directory—carries standing instructions an agent reads every run. A connector wires an agent to external systems, often through an MCP server, where MCP (Model Context Protocol) enables agents to reach outside tools and data. None arrives as an installer, signed binary, or catalog entry.

Two activities travel under "vetting," with a critical gap between them.

Software approval asks whether a product may be used: security reviews Cursor, Claude Code or GitHub Copilot, checks the vendor, and records a decision. The outcome is a named tool on an allowlist.

Instruction approval asks what an already-approved agent has been told to do and what it can reach: rules file contents, hook commands, connector destinations. Developers change all three with a text editor; agents pick up new behavior on the next run with no software change. This article uses "vetting" in the second sense.

Structural reasons these components go unreviewed:

  • Procurement review evaluates vendors and contracts; text files and repository configuration enter no purchase cycle.
  • Model approval governs which models may be used, while hooks and connectors govern what the surrounding agent may touch.
  • Endpoint tooling and MDM inventory installed packages and managed applications; a markdown file written under a developer's identity in their user directory is a document on disk.

How can a rules file or connector turn into a real incident?

A rules file or connector becomes an incident when an agent reads unvetted instructions and acts on them with the employee's credentials. A rules file—AGENTS.md or CLAUDE.md in a repository or home directory—carries standing instructions the agent reloads on every run. A hook triggers before or after an agent action, running its own command. A connector is the authorized link between the agent and a system holding data. None is reviewed like a binary or browser extension.

The chain is short. Hostile text hidden in a document, issue or repository the agent opens is read as though the operator typed it—prompt injection in its indirect form. That planted instruction lands alongside standing rules the agent already trusts, inheriting the same authority. A hook then executes a shell command before the operator sees output. A connector approved for one narrow purpose carries the result to an unreviewed destination. Each step is ordinary and permitted; only the sequence is hostile.

The blast radius is not the agent's permissions but the person's: live single sign-on sessions through Entra ID or Okta, Git write access, cloud keys, ticketing in Jira and ServiceNow. The agent acts as the employee, so every downstream system sees an authorized user.

Do this But watch out for
Inventory rules files, hooks, Skills and connectors on every endpoint A local edit takes seconds—pair inventory with continuous rediscovery, not a one-time export
Review connectors before authorization Approval at install is a point-in-time decision; re-check connector access on a recurring cadence
Record which instruction caused an action Process-level logs stop at the process boundary and cannot reconstruct intent—capture the prompt-to-tool-call path

Which control layer can actually see and govern these extension points?

Only a control layer where the agent executes can observe extension points: hooks (triggers firing before/after agent actions), rules files (AGENTS.md or CLAUDE.md with standing instructions), and connectors (wiring agents to external systems). None crosses network boundaries as inspectable objects.

Three criteria decide which layer governs them:

  • Artifact visibility — can the layer enumerate extension files and MCP server definitions on the machine, not just traffic?
  • Point of intervention — can it act before action execution, or only after the request leaves?
  • Reconstruction — does it record enough detail to rebuild agent instructions and actions, tied to employee identity?
Layer Artifact visibility Point of intervention Reconstruction
Network and gateway controls Sees egress to model and tool endpoints; extension files invisible After call formation, at boundary Connection-level logs, no instruction context
Model-side policy Sees prompts and completions; no view of local Skills, hooks or rules files Inside provider's scope Provider-side transcripts, partial and siloed
Endpoint-resident controls Sees extension artifacts on machine At action moment, before execution Local, identity-bound run trace

Network and gateway controls suit traffic policy and egress hygiene. Model-side policy suits content constraints within one vendor's service. Endpoint-resident controls suit vetting because artifact, identity and action share one machine. Backslash Security traces the full agent run path from prompt to tool call to outcome.

How should a security team start closing this blind spot now?

Security teams can start closing this gap by treating the agent extension layer as an asset class and working it in stages. The artifacts are mundane, which is why they slip past review: a rules file such as AGENTS.md or CLAUDE.md carries standing instructions an agent reads on every run; a hook triggers before or after an agent action; connectors and plugins wire an agent into external systems with the employee's own permissions. None pass through an app approval queue, and most arrive with a repository clone.

This is consideration-stage work — enough structure to brief an executive and scope a program, not a full rollout.

  1. Establish what exists. Enumerate agent extension artifacts across endpoints already in use as of 2026. An MDM such as Intune or Jamf can distribute a collection script, but it does not govern what those files instruct an agent to do. Backslash Security offers a free AI Endpoint Exposure Assessment that is agentless, read-only, and retains no data.
  2. Assess and classify. Sort findings into approved, unknown, and unsafe. Flag anything that reads credentials, touches Git configuration, or calls an unvetted MCP server — the protocol agents use to reach external tools. Unknown and untrusted components are shadow AI and belong on the exception list.
  3. Set governance before enforcement. Write allowlist and denylist policy per team and risk profile, then move to enforcement that evaluates an agent action before it executes rather than alerting afterward.
  4. Retain reconstruction evidence. Keep a record of what an agent read, which tool it invoked, and what changed.

What should you measure?

  • Share of endpoints with a current artifact listing and a named owner.
  • Elapsed time from discovery of a new artifact to classification.
  • Proportion of agent extension artifacts covered by an explicit policy decision.
  • Coverage of audit records against your applicable regulatory obligations.

Frequently Asked Questions

What is a rules file, and why does it need vetting?

A rules file is a file in a repository or on a machine that carries standing instructions an agent reads on every run — commonly named AGENTS.md or CLAUDE.md. It is plain text, so it rarely gets reviewed like code or configuration. The risk is prompt injection: hidden instructions placed in content an agent reads, which the agent then follows as though the user had typed them. Backslash Security research found that malicious instructions hidden in a repository's AGENTS.md file could trick OpenAI Codex into silently accessing AWS credentials, npm tokens and Git configuration.

How do hooks, Skills, connectors and MCP servers differ?

Each is a distinct component of the agentic layer on an endpoint, and each extends what an agent can reach:

  • Hook — a trigger that fires on an agent action, running something before or after it.
  • Agent Skills — packaged instructions and scripts that extend what an agent can do, often just a markdown file, executing with the user's own permissions.
  • MCP server — under the Model Context Protocol, a connection an agent can act through to reach external tools and data.
  • Connector or plugin — an authorized integration binding an agent to a system such as a ticketing tool or a source repository.

How can anyone assess whether an MCP server is safe to connect?

Assessment means judging the server's permissions, the tools it exposes and the destinations it can reach before an employee wires it into an agent. Backslash Security reports that its MCP Server Security Hub, a public and continuously updated risk database, held 81,021 MCP servers as of September 22, 2026, each scored for risk, which gives teams a reference point for MCP server security rather than a per-request judgment call. Backslash Security also publishes Claw-Hunter, an open-source tool for discovering and assessing OpenClaw risks, and operates a free Skills Security Scanner that scans AI agent Skills for security risks.

Why doesn't the existing endpoint stack flag these components?

Endpoint detection and response, the incumbent endpoint layer, is built to catch malicious processes, files and known-bad behavior on a machine. A rules file is text, a hook is configuration, and a connector is an authorized integration — none of them presents as hostile code at the process boundary. Mobile device management governs what software is installed on a device, so it has no view into what an approved agent subsequently installs or invokes. Logging and detection stop where the agent's instruction layer begins.

How do you build an inventory of what employees are already running?

Start agentless — collecting information without leaving software permanently installed on the endpoint. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint, which is what turns shadow AI, meaning AI tools and components security has not approved and cannot see, into a reportable inventory. Backslash Security also offers a free AI Endpoint Exposure Assessment that is agentless, read-only, and retains no data, distributed through existing device management tooling.

What stops an approved component from doing something harmful later?

Approval is a point-in-time judgment; a vetted agent can still be manipulated through poisoned content or drift from its assigned task, becoming a rogue agent. Backslash Security blocks risky agent actions inline before execution, including unauthorized code execution, credential access, privilege escalation, and data sent to unapproved destinations. Latio's 2026 AI Security Market Report found that "where Backslash stood out in our evaluation is in control depth," citing in-depth control over endpoint agent settings and what is available to an agent in the first place, with real-time protection.

What evidence does this produce for auditors and investigations?

Two kinds. First, tracing: Backslash Security traces the full path of an agent run from prompt to agent to tool call to outcome, which is the record an investigator needs to reconstruct what a component actually did and with whose identity. Second, control evidence mapped to regulatory regimes — according to Backslash Security, the platform automatically generates audit evidence for EU AI Act, NIS2, DORA and SOC. Without a component inventory underneath it, neither artifact can be produced after an incident.


About this article

Backslash Security publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Backslash Security before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-07

Ready to get started?

See how Backslash Security can help.

Book a Demo