Agent Artifacts on the Endpoint

8 min read

S26
Operation · Safety, Alignment & Agentic Security

Your agent's operational identity is a directory in someone's home folder.

Every control you built for agent security assumes the agent is the thing under attack — the prompt, the tool call, the sandbox. Meanwhile the agent's tokens, its list of connected systems, and a searchable record of everything it has ever been asked now sit in predictable paths on laptops you do not monitor, and commodity credential-stealing malware started collecting exactly those paths. Gen Threat Labs published collection rules on 8 September 2026 naming Claude, Cursor, Cline, Continue, Codex and OpenCode artifacts; adding a new agent to that list is a configuration push, not a new exploit. Treat the developer endpoint as a production surface with an inventory, or accept that your most privileged credential has no owner.

STEP 1

Enumerate the artifact set before you argue about controls.

Nobody defends this surface because nobody has written down what is on it. Do that first, by hand, on one real machine, for one real agent install. Five categories come up every time, and they are not equally bad.

  • Credentials. Access tokens, refresh tokens, API keys. Claude Code, for example, keeps its login in the OS keychain where it can and falls back to ~/.claude/.credentials.json at mode 0600 otherwise; a September 2026 report against the project records that file holding a live access token beside a refresh token valid for twenty-seven days.
  • Connection configuration. MCP server definitions: endpoints, headers, environment variables, and very often the credentials for the services behind them, inline.
  • Conversation and prompt history. Local databases and transcript files. These contain source code, pasted secrets, customer names, and the reasoning about your systems that an attacker would otherwise have to reconstruct.
  • Project and session metadata. Which repositories, which hosts, which tickets, which branches. Cheap-looking, and the most useful thing in the set for targeting.
  • Harness configuration. Hooks, allowlists, auto-approve settings and skill directories — the files that decide what runs without asking. See lifecycle hooks and harness config.

The honest summary of that list: the endpoint holds the credential, the map of what the credential reaches, and the history of what it was used for. In a server-side system those three live in three different trust zones with three different review processes. On a laptop they live in one directory, under one user, with no owner in your org chart.

STEP 2

The controls you have do not apply, and it is worth being precise about why.

This is the step teams skip, and skipping it produces the wrong fix — usually a policy telling developers to be careful. Go through the actual controls one at a time.

  • File mode is a user boundary, not a process boundary. 0600 stops another user on the same host. A stealer that got onto the machine is running as that user, which means the mode bits are satisfied, not bypassed. Nothing is broken and nothing alerts.
  • Your gateway sees the agent, not the thief. If a harvested token is replayed against the same provider API from somewhere else, the request looks like your agent. Your egress controls govern traffic leaving your network; the replay does not leave your network.
  • Secrets management stops at the server. The practices in secrets management for agents — short leases, injection at runtime, no secrets at rest — are the right practices, and almost nobody applies them to the config file on a workstation.
  • Prompt-injection defence is aimed at a different attacker. There is no injection here, no jailbreak, no tool-poisoning, no model involvement at all. The agent is not tricked. It is burgled while it sleeps.
  • The economics run against you. Gen's published rules are remotely managed — folders, filenames, extensions, limits — so covering a newly popular agent is a configuration update delivered to machines that are already compromised. Gen recorded infostealer detections against 3.3 million unique protected users in the first half of 2026. The marginal cost of adding your tooling to that pipeline is approximately zero.
STEP 3

Price each artifact by what it buys, not by what it is called.

Ranking matters because you will not fix all five categories this quarter. Price them by what a holder can do with the artifact alone, with no further access and no interaction with your systems.

  • A refresh token is worth more than a password. A password often meets MFA. A refresh token is the post-MFA object: it renews without re-authentication, so it is a standing grant with a multi-week clock. See credential lifetime for why the access token's short TTL does not help here.
  • An MCP config is worth more than any single credential in it. It is an enumerated list of the systems you consider worth connecting an agent to, with the endpoints and headers to reach them. It converts a generic theft into a targeted one — the subject of configuration as reconnaissance.
  • Transcript history is worth more than you will want to admit. Treat one week of a senior engineer's agent history as equivalent to read access on the repositories and the incident channel, because in content terms it very nearly is.
  • Project metadata is the cheapest intelligence in the set. No parsing, no secrets, just a precise answer to "which organisation is this and what do they run".

One consequence of that ranking is worth stating plainly: rotating the API key while leaving the refresh token and the MCP config in place is not remediation. It is the easiest of the four and the least load-bearing.

STEP 4

Build the artifact inventory, generated rather than written.

You cannot own what you have not listed, and a hand-written list is wrong within a month because every agent release moves files. Generate it, and keep it next to the registry you already maintain for server-side agents — agent inventory and registry is the same discipline with a different host.

  • One row per artifact path, per tool, per OS. Paths differ across macOS, Linux and Windows, and the keychain-versus-file decision is often made at runtime by whether the keychain was unlocked. Record both branches.
  • Each row carries an owner and a revocation path. Who can kill this, by what mechanism, and how long it takes. Rows where the answer is unknown are your actual findings.
  • Each row carries a sensitivity class. Use the ranking from the previous step so the inventory tells you what to fix first instead of just how much there is.
  • Refresh it from the tools' own documentation on a schedule. Agent CLIs change storage locations between minor versions. Treat it like unpinned vendor defaults: the default moved, and nobody announced it to you.
  • Count the laptops. The inventory is per-artifact-type; the exposure is that number multiplied by every machine with the tool installed, including contractors' and the one in a drawer.
STEP 5

Make the artifact worth less, since you cannot keep it from being read.

The design goal is not an unreadable file. It is a file whose contents expire or point elsewhere, so that a successful read yields something with a short half-life. Four changes do most of the work, in rough order of return.

  • Remove inline secrets from MCP configs. Reference a secret by name and resolve it at launch from the OS keychain, a secret agent, or a short-lived broker. The config then names your systems without authenticating to them — which still matters, but it is one artifact instead of two.
  • Shorten the pair, not the token. Push for provider options that bind refresh to a device or shorten refresh validity for workstation installs, and prefer per-project credentials over one account-wide login. This is scoped credentials applied to the human's machine.
  • Cap history retention locally. Agent transcripts default to keeping everything forever because that is what users want. Set a retention window, and redact on write where the tool supports it — the same argument as PII redaction in agent traces, applied before the data reaches a disk you do not control.
  • Separate the privileged install from the exploratory one. The agent that can reach production should not be the same install that opens arbitrary repositories and runs arbitrary MCP servers. One profile per blast radius, which is the cheapest structural fix available here.
STEP 6

Detect the replay, and rehearse the revocation you will need.

Assume one laptop's artifacts are already gone. Two questions decide how that day goes: would you know, and how fast can you make it stop. Neither is answered by the endpoint agent on the laptop, because by the time you are asking, the credential is being used from somewhere else entirely.

  • Put a honeytoken in the MCP config. A server definition no legitimate workflow ever calls, pointing at an endpoint you own, is the one unambiguous signal available on this surface: nothing but a reader of that file would ever touch it. Honeytokens for agent systems has the placement rules.
  • Alert on provider-side use that does not match the install. New region, new client fingerprint, use while the owning laptop is asleep, two concurrent sessions on one credential. This is the signal detecting agent compromise builds on, and it lives at the provider, not on the host.
  • Write the revocation runbook per artifact class. Provider token, MCP-referenced service credential, cached repository token. Different mechanisms, different owners, different latencies. Discovering that during an incident costs hours you will not have.
  • Time it once, with a stopwatch. Revoke a real agent credential on a volunteer's machine and record the wall-clock gap until the next call failed. That number is the one you will be asked for, and the drill usually finds a copy nobody listed.
  • Decide in advance what a compromised transcript triggers. Unlike a token, history cannot be revoked. The response is scoped to what was in it — which is why the retention cap in the previous step is also an incident-response control.

Start here this week, in this order. Run your inventory script on one engineer's machine with production reach and read the output out loud in a review — the list itself does the persuading. Strip inline secrets out of MCP configs and replace them with references; it is a day of work and it removes the highest-leverage artifact. Then plant one honeytoken MCP entry per install and time one revocation. Only after those three is it worth opening the argument about managed devices and full-disk policy, which is slower, more political, and does not change what is in the file.