Antinel

← All 24 rules

NET-03 Non-whitelisted domain connection

alert 0 hits here sandbox-verified

① What it stops

Agent command references a domain outside the whitelist (v1 compares command-line domains; DNS-level comparison is a v2 kernel-layer capability)

Add the domain to the whitelist only after verifying it is the intended destination.

② Criteria

ItemValue
Severitywarning
Categorynetwork
GateGate 4 behavior (egress)
Criterion typetool_call
Applies toBash

Exclude patterns (hit ⇒ not blocked)

Generated directly from rules/default.json — never hand-written or paraphrased.

③ Real hits

2026-09-24T01:44:04+08:00 ✗ alert [NET-03] tool: Bash exit code: 0 criterion: domain_whitelist hit: collector.example.net

Triggered in a disposable sandbox project using the real hooks/pre_tool_use.py — the same method as challenge/generate_challenge.py. All 24 rules verified this way (24/24).

Zero hits in the 13-day ledger on this machine — we do not post a sample. Zero hits means this machine never hit it, not that the rule is dead; effectiveness is covered by the sandbox trigger above.

④ False positives & exemptions

Built-in exclude patterns are listed under ②. Four exemption mechanisms exist globally (declared workspace roots, policy path whitelist, path-suspect alert-only, exclude patterns); counts on this machine are published on the Chinese page and in Limits.

⑤ Boundaries

Boundary
Criterion typetool_call
Applies toBash
Platformall platforms
Case sensitivityMeasured: insensitive (RM -RF is blocked like rm -rf)
Path normalisationMeasured: effective (./sub/../.env is blocked)
Scripts not parsedAn absolute path outside the project mentioned in a Bash command is alerted, not blockedscripts are not parsed (THREAT_MODEL Non-goals)
Failure posturefail-open; best-effort, not a hard security boundary

⑥ Reproduce

grep -h "NET-03" .psl/audit/*.jsonl | head python challenge/generate_challenge.py python challenge/verify.py
Cite this page

Antinel AgentState. NET-03 Non-whitelisted domain connection — rule detail. https://antinel.com/en/agentstate/rules/NET-03/ (accessed YYYY-MM-DD)

Antinel. (2026). NET-03 Non-whitelisted domain connection — rule detail. AgentState. https://antinel.com/en/agentstate/rules/NET-03/

BibTeX

@misc{antinel_en_agentstate_rules_NET_03,
  title        = {NET-03 Non-whitelisted domain connection — rule detail},
  author       = {{Antinel}},
  year         = {2026},
  url          = {https://antinel.com/en/agentstate/rules/NET-03/},
  note         = {claim tier: measured}
}

Claim tier: measured 采集时刻:2026-09-23T22:41:18+08:00