Antinel

All 24 rules

Every rule published, with field-level criteria — not a summary.

critical 17 / warning 7 / total 24. "hits here" = times this rule blocked on this one machine over 13 days (as of 2026-09-23).

#IDWhat it stopsSeverityHits here
1SEC-01Agent attempted to read a .env file which may contain API keys and secretsblock15
2SEC-02Agent attempted to read SSH private key or authorized_keys fileblock0
3SEC-03Agent attempted to read cloud provider credentialsblock0
4SEC-04Agent attempted to read cryptocurrency wallet or keystore fileblock2
5SEC-05Agent attempted to read browser stored data (cookies, passwords, sessions)block0
6NET-01Agent made an external network request via shell command to a non-whitelisted domainalert0
7NET-02Agent code contains Python network request callsalert0
8NET-03Agent command references a domain outside the whitelist (v1 compares command-line domains; DNS-level comparison is a v2 kernel-layer capability)alert0
9DST-01Agent executed a file or directory deletion commandblock68
10DST-02Agent attempted to write to a file outside the project root directoryblock28
11DST-03Agent attempted to modify shell startup configuration (persistence mechanism)block0
12DST-04Agent attempted to establish persistence (cron job, systemd service, startup item, scheduled task, registry Run key)block0
13DST-05Agent attempted to escalate privilegesalert0
14CTX-01Agent attempted to enumerate all environment variables (may expose API keys and secrets)alert0
15CTX-02Potential prompt injection payload detected in skill instruction fileblock0
16CTX-03Invisible Unicode character detected (tag characters, zero-width, word joiner, BOM in middle of file)block2
17CTX-04Long base64 or hex string detected (potential encoded payload)alert0
18CTX-05SKILL.md frontmatter name field does not match parent directory namealert0
19DST-06Agent downloaded a remote script and piped it straight into a shell or interpreterblock1
20DST-07Agent ran a git command that irreversibly discards working-tree changes or untracked filesblock0
21SEC-06Secret-looking literal (API key, private key, token) appeared in written or edited contentblock1
22DST-08Agent attempted to destroy permissions or ownership recursively (denial of service)block0
23DST-09Agent attempted to write an NTFS alternate data stream (path:stream) -- invisible to dir/ls and carried along by a plain file copyblock0
24DST-10Agent attempted to write an NTFS alternate data stream from a shell (redirect / -Stream / copy / open) -- the command-line half of DST-09block3

Severity: block = the call is stopped; alert = allowed but recorded (another 511 alert records). Zero hits does not mean the rule is dead — it means this machine never encountered it. Every rule's effectiveness is verified by sandbox trigger (24/24).

Limits → Real cases →

Cite this page

Antinel AgentState. All 24 rules — AgentState. https://antinel.com/en/agentstate/rules/ (accessed YYYY-MM-DD)

Antinel. (2026). All 24 rules — AgentState. AgentState. https://antinel.com/en/agentstate/rules/

BibTeX

@misc{antinel_en_agentstate_rules,
  title        = {All 24 rules — AgentState},
  author       = {{Antinel}},
  year         = {2026},
  url          = {https://antinel.com/en/agentstate/rules/},
  note         = {claim tier: measured}
}

Claim tier: measured 采集时刻:2026-09-23T22:41:18+08:00