How it gets overlooked
Your agent needs documentation. A moment later, its command points at a host you have never seen in this workflow. The destination may be legitimate. But without context, a new host is just another line in the terminal.
Imagine an agent that normally uses a familiar package index. During a task, an unfamiliar destination appears in its recorded tool arguments. The important question is why that destination belongs in this session.
What ClawMetry detects
ClawMetry compares observed host references with the learned cohort baseline. A host absent from that baseline can raise a network egress warning. The finding identifies the new host and the reason it was considered unusual.
The difference that changes the finding
Triggering example
collector.invalid
Warning finding
Quiet comparison
pypi.org in baseline
No finding for this detector.
In the checked example, the baseline contains the familiar package host. That host stays quiet. A different host raises a first time destination finding. This comparison needs a learned baseline; a fresh install does not already know your normal destinations.
Inspect the detector result
{
"kind": "network_egress",
"severity": "warning",
"evidence": {
"ground": "first_time",
"distinct_hosts": 1,
"hosts": [
"collector.invalid"
],
"new_hosts": [
"collector.invalid"
],
"settling_hosts": [],
"raw_addresses": [],
"known_host_count": 1,
"threshold": 8,
"write_hosts": [],
"read_only_writes": [],
"observed": "tool_arguments"
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Inspect the command and the surrounding task. Was the agent fetching documentation, installing a dependency or attempting a write? Check the destination ownership and any sensitive activity that came before it. Use those facts to decide whether the action was expected.
- Inspect the command
- Verify the destination
- Check preceding activity
What this signal establishes
Host references come from tool arguments, not packet capture. A new host does not prove a connection succeeded or data was exfiltrated.