Detector libraryAgent config tamper

Agent config tamper

Who changed the agent rules?

Notice hooks and changes to the files that guide an agent.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

Your task stayed the same, but the agent configuration changed. A hook or instruction file can influence what happens around ordinary work. That makes the configuration itself something worth watching.

Consider a workspace with a hook command in the agent settings. The visible task may never mention that hook. Separately, changes to instruction and settings files after their first inventory can alter the environment the agent is following.

What ClawMetry detects

ClawMetry reports supported agent hook commands it did not install, and relevant configuration changes after a baseline exists. The finding identifies the configuration source so an operator can inspect the change in context.

The difference that changes the finding

Triggering example

Foreign hook command

Critical finding

Quiet comparison

ClawMetry hook only

No finding for this detector.

In the checked example, a foreign hook command in the settings file raises a critical finding. A file containing only the recognized ClawMetry hook stays quiet. This distinction keeps the observer’s own supported hook from becoming a warning by itself.

Inspect the detector result
{
  "kind": "agent_config_tamper",
  "severity": "critical",
  "evidence": {
    "file": ".claude/settings.local.json",
    "commands": [
      "node review-hook.js"
    ],
    "count": 1,
    "gitignored_by_convention": true,
    "observed": "agent_config",
    "readers": [
      "claude_code",
      "cursor"
    ],
    "events": [
      "Stop"
    ]
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Review the hook or file diff and compare it with expected setup changes. Establish who authorized it using your own change history. If the change is legitimate, retain that context; if it is unexpected, investigate before relying on later agent activity.

  1. Inspect the hook or diff
  2. Check authorized changes
  3. Review affected sessions

What this signal establishes

A finding does not identify the author or prove tampering was malicious. Changes made before the first inventory are part of the baseline.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.