





It is data leaving the organization through an AI agent's own legitimate activity rather than through a recognizable attack. An agent with excessive or escalated permissions can autonomously read credentials, source code and enterprise data, then move them out through trusted MCP servers, connectors and APIs. Every component involved is approved, every call looks ordinary, and no malware is present.
DLP waits for the data to move, then tries to classify it as sensitive. That is the wrong moment and the wrong signal for agentic activity, because the transfer happens through sanctioned channels under a valid user identity. Backslash works a step earlier, identifying and blocking the malicious skill, poisoned hook, unsafe instruction or risky agent behavior that enables the transfer in the first place.
Yes. Excessive permissions are enough on their own - an agent given broad file and network access will read credential files and reach external services as part of completing an ordinary task. Attacks make it faster, but they are not required. This is why permission scope matters more than threat detection here.
Through the files and components it already trusts. Our research found that instructions hidden in a repository's AGENTS.md could cause OpenAI Codex to silently access AWS credentials, npm tokens and Git configuration. In a separate finding, malicious repository configurations redirected Claude Code API requests to an attacker-controlled server, exposing the user's sign-in token - a credential that allows running AI workloads, uploading files and starting sessions under the victim's identity.
Reach. A sign-in token for an AI tool can allow an attacker to run workloads, access profile information, upload files and initiate sessions as the victim - with the agent's own permissions behind each action. Nothing about that activity appears anomalous, because it is the same identity doing the same kinds of things it always does.
Because most of the relevant activity never crosses the network in a form a gateway can inspect, and what does cross it is a valid call to a legitimate service. A gateway sees an authorized request to an approved destination. It has no visibility into which skill instructed the agent, which MCP tool was invoked, or whether the retrieval was part of the task the user asked for.
Commands and actions that enable a transfer: collecting environment variables, retrieving credentials, packaging source code, connecting to an unauthorized service, or instructing a tool to transmit enterprise information. The malicious skill, hook, instruction or agent action is blocked before the workflow reaches the data or completes the transfer.
Yes, and this is the case per-component scanning misses entirely. A skill that retrieves credentials, a hook that executes unsafe commands, and an MCP tool with unnecessary access may each pass review individually while together forming a working exfiltration path. Backslash assesses components in combination, not only one at a time.
You need an inventory of the operational context, not just the applications. That means every AI agent, skill, MCP server, connector, plugin, hook, rules file and agent configuration across employee endpoints - including anything installed under personal accounts or outside security oversight. Discovery is the first of the four stages, because nothing downstream is possible without it.
The chain connecting intent to outcome - which component introduced the behavior, what the agent accessed, which tools it called, and where data was sent. That sequence is what separates a malicious component from a legitimate but overscoped action, and it is the first question asked in any investigation.