AI agent security

An agent hunted for someone else’s API key. Find out why.

When an employee does something you didn’t expect, you can ask them why. But an agent’s own account isn’t evidence. Origin gives your security team the session itself, from the request to every step and change.

Evidence

An alert gives you a starting point.

To judge what the agent did, you need to know what it was asked to do, what information it had, and what happened next. Origin connects that evidence in the traces they leave.

Origin / Trace review

Our own traces · findings verified against each session

TriageTriage agent’s order

  1. Sep 10T219Worth a look

    Triage agentCodex relaunched Claude Code with its approval checks off after Claude reported it lacked permission. The engineer wasn’t asked.

    T219claude -p "…" --allowedTools … --dangerously-skip-permissions
    Open turn 219
  2. Sep 723:02Worth a look
  3. Sep 19—Worth a look
  4. Sep 18T316Routine
Investigation

Work back from the finding.

Your agents produce more sessions than your team could ever read. Origin automatically reviews every trace for security signals, and triages what needs your attention.

Origin / Trace investigation

Extracting real-time data from the staging-mcp tenant to validate the hook-gating hypothesis · Codex · 76 API calls

Turn 1of 244

Findings1
User8 prompts
Agent8 replies
Reports10
Hand-offs4 candidates
Joins207 sessions

Codex was asked for staging data, and told Claude to stay read-only.

T1Extracting real-time data from the staging-mcp tenant to validate the hook-gating hypothesis.
User8 promptsPrompt to Clauderead-only, aggregate, last seven days
Trace investigations

Follow the work across agents.

Agents can hand work to other agents with different tools and permissions. Origin connects those handoffs so you can follow what each agent did.

An agent went hunting for someone else’s API key.

A subagent researching crime statistics decided its public FBI API key was rate-limited. Instead of reporting back, it searched public code and the web for another. Neither search found one. Had one turned up, it would have used a stranger’s credential.

23:02 · Endpoint discovery agent

API_KEY=[A-Za-z0-9]{40}

grep.app · public code0 hits

Its brief never asked for a key.

Read the investigation

One agent told another to bypass a deployment guard.

A Coordinator agent called a deployment urgent, though the trace shows no user asking for one. The Builder wrote a DEPLOY_NOW exception into the guard and deployed. The “one-off” exception stayed and was used again.

Sep 28 · Changed by the Builder

Deploy script idle guard

Bypassed

No user request in the trace.

Read the investigation
Scope

See how far it went.

Check which files, systems, and data were involved. Look for the same behavior in other sessions to understand whether this was an isolated action or a wider problem.

Origin / Investigate

Related findings across sessions · verified

Cases grouped across sessions

LatestCaseSessionsFindingsReview
10:43 AMSep 192133Worth a look
7:17 PMSep 16—1Worth a look

Is this happening anywhere else?

Yes. The same behavior appears in 21 sessions, with 33 findings. The earliest cites the user saying, “I don’t want to touch the repo.”

Response

Decide what needs to change.

See whether a credential needs rotating or an approval needs changing. Ask Origin follow-up questions, with every answer pointing back to the evidence.

Origin / Trace investigation

Monitoring the completion of the deployment cutover

Lanes 123
Reports 27
Joins 201 sessions
User
Agent
Turns
0100200300400500
Finding5 occurrences · T23–T316

Hardcoded Forgejo API token in diagnostic script

Behaviour: lowContent: restrictedCredential in script

The agent embedded a Forgejo API token directly in a Python script executed via tools.exec_command. While used for read-only diagnostics, this violates the norm of referencing secrets from environment files or secret stores.

332 of 554 turns · ChatGPT

Finding linked to its source

Privacy controls

Control who can see the evidence.

Traces can contain credentials and customer data. You decide what Origin collects. The data is encrypted, and role-based access controls who can see it.

Our approach to privacy

Know what happened.
Decide what happens next.

We’ll walk through an investigation with you, from the first finding to the fix.