How it gets overlooked
One agent writes to a destination. Another does the same. Then several more. Each session may look unremarkable on its own, while the fleet pattern tells you something worth investigating.
Imagine six unrelated sessions writing under the same unfamiliar destination prefix. A per session review sees one action at a time. The missing question is whether independent agents have started doing the same unusual thing together.
What ClawMetry detects
ClawMetry groups supported write actions by method, host and normalized path prefix. With enough node history, it checks whether an unusual fingerprint is shared by enough unrelated session families. A match creates a coordinated action warning with the participating sessions.
The difference that changes the finding
Triggering example
6 unrelated families
Warning finding
Quiet comparison
1 orchestrator family
No finding for this detector.
The checked example has six unrelated sessions sharing a new write fingerprint and produces one finding. Link the same sessions to one orchestrator, and they count as one family instead. The detector stays quiet because expected parent and subagent cooperation is different from independent convergence.
Inspect the detector result
{
"kind": "coordinated_action",
"severity": "warning",
"evidence": {
"fingerprint": {
"verb": "PUT",
"host": "collector.invalid",
"path_prefix": "/shared/board"
},
"fingerprint_key": "PUT collector.invalid/shared/board",
"families": 6,
"sessions": 6,
"session_ids": [
"claude_code:session0",
"claude_code:session1",
"claude_code:session2",
"claude_code:session3",
"claude_code:session4",
"claude_code:session5"
],
"threshold": 5,
"first_seen_by_node": null,
"settle_hours": 24.0,
"observed": "tool_arguments"
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Inspect the shared destination and compare the participants tasks. Was there an intended rollout or a common dependency? Follow the sessions back to the source of the behavior. Review the fleet together rather than dismissing each action in isolation.
- Inspect the shared destination
- Compare participant tasks
- Trace the common source
What this signal establishes
This uses captured tool arguments, not network traffic. It requires settled history and does not prove collaboration, compromise or successful writes.