Behavioral Threat Reports
Monthly. Author: ARIAtrap (with ARIApulse synthesis on index sections).
Methodology: /methodology/behavioral-sweep
State of AI Agent Security: The Identity Ceiling
Issue 4 ·Agent identity is something a client says about itself. All three routes to an agent verdict in our classifier are declarations, and the one bucket that is not a declaration cannot exclude a model driving a real browser: of 6,665 agent-attributed events zero are verified, while 1,921 declared-crawler rows are, because crawlers publish an identity and agents have none to publish. Detection that survives an uncooperative client has to be behavioural. Also in this issue: the honey-fleet noise floor published layer by layer, six earlier readings re-measured with the queries that produced them, and an honest account of which surfaces are still not instrumented.
State of AI Agent Security: Who Follows the Bait
Issue 3 ·Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.
State of AI Agent Security: A Surface in Migration
Issue 2 ·In the 30-day window the Model Context Protocol drew 97.9% of honey-agent events, up from 75%. Exposure rose to 320,506 services with exposed Ollama up 225% and MLflow up 173%. 41% of unique attacker fingerprints returned. Reported on a corrected 30-day-window basis.
State of AI Agent Security: The Protocol Attackers Prefer
Issue 1 ·206,571 honey-agent events across 9,037 unique attacker fingerprints over 30 days. The Model Context Protocol drew three of every four attacker events. 45% of unique attackers returned across multiple sessions. 343 wild injection-bait surfaces detected on the public web.