Detector libraryCoordinated action

Coordinated action

Separate agents. The same destination.

Spot an unusual shared write pattern across unrelated sessions.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

One agent writes to a destination. Another does the same. Then several more. Each session may look unremarkable on its own, while the fleet pattern tells you something worth investigating.

Imagine six unrelated sessions writing under the same unfamiliar destination prefix. A per session review sees one action at a time. The missing question is whether independent agents have started doing the same unusual thing together.

What ClawMetry detects

ClawMetry groups supported write actions by method, host and normalized path prefix. With enough node history, it checks whether an unusual fingerprint is shared by enough unrelated session families. A match creates a coordinated action warning with the participating sessions.

The difference that changes the finding

Triggering example

6 unrelated families

Warning finding

Quiet comparison

1 orchestrator family

No finding for this detector.

The checked example has six unrelated sessions sharing a new write fingerprint and produces one finding. Link the same sessions to one orchestrator, and they count as one family instead. The detector stays quiet because expected parent and subagent cooperation is different from independent convergence.

Inspect the detector result
{
  "kind": "coordinated_action",
  "severity": "warning",
  "evidence": {
    "fingerprint": {
      "verb": "PUT",
      "host": "collector.invalid",
      "path_prefix": "/shared/board"
    },
    "fingerprint_key": "PUT collector.invalid/shared/board",
    "families": 6,
    "sessions": 6,
    "session_ids": [
      "claude_code:session0",
      "claude_code:session1",
      "claude_code:session2",
      "claude_code:session3",
      "claude_code:session4",
      "claude_code:session5"
    ],
    "threshold": 5,
    "first_seen_by_node": null,
    "settle_hours": 24.0,
    "observed": "tool_arguments"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Inspect the shared destination and compare the participants tasks. Was there an intended rollout or a common dependency? Follow the sessions back to the source of the behavior. Review the fleet together rather than dismissing each action in isolation.

  1. Inspect the shared destination
  2. Compare participant tasks
  3. Trace the common source

What this signal establishes

This uses captured tool arguments, not network traffic. It requires settled history and does not prove collaboration, compromise or successful writes.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.