/00·ENDPOINT POSTURE BRIEFING — CONFIDENTIAL

AI Coding Tool
Exposure.

5 coding agents are in use on the endpoint. 3 critical findings need action this week.

  • Customer · Example Corp
  • Engagement · 2026-07-11
  • Operator · Demo Operator
  • Manifest SHA-256 · manifest not pre…
01 · EVIDENCE STATUS Local endpoint collection
Detected tools5
Not detected0
Findings6
critical 3 high 2 medium 1 low 0
ToolStatusDurationCollector
Claude Codedetected-1.0.0
Cursordetected-1.0.0
Codex Desktopdetected-1.0.0
GitHub Copilotdetected-1.0.0
Grok Builddetected-1.0.0
/01 EXECUTIVE SUMMARY

6 findings. 3 require action this week.

Claude Code, Cursor, Codex Desktop, GitHub Copilot and Grok Build are in active use. The items below represent durable secret exposure, persistent permission state with no prompt, and runtime configuration that bypasses sandboxing.

Critical
3
action this week
High
2
30-day window
Medium
1
policy / backlog
Low
0
informational
severity distribution · n = 6 1 / 2 high are gitleaks hits · grouped in appendix
3CRIT
2HIGH
1MED
/01

.env file found in git commit history

Git Posture·collector: git-posture
critical

project#demo

Category

Git Posture

Evidence count

1 row

Reference

evidence/git-posture.json

CRIT-01 git posture
/02

Codex sandbox bypass observed

Shell Execution·collector: codex
critical

sandbox=disabled

Category

Shell Execution

Evidence count

1 row

Reference

evidence/codex.json

CRIT-02 shell execution
/03

Grok Build permission_mode is always-approve

Shell Execution·collector: grok
critical

permission_mode=always-approve yolo=true

Category

Shell Execution

Evidence count

1 row

Reference

evidence/grok.json

CRIT-03 shell execution
/02 POSTURE AT A GLANCE

Where each tool stands.

Detected tools, highest observed risk, and permission, approval, and activity counts, side by side.

PlatformDetectedHighest-riskMCP rulesStored allow rulesApproval evidenceChat msgsActive est.
Claude Codeyescritical11available via OTEL3 files-
Codex Desktopyescritical01-2 files-
Grok Buildyescritical10bypassed1 files-
Cursoryesnone00-6 files-
GitHub Copilotyesnone00---

Stored allow rules are durable non-MCP permission entries. Approval evidence shows recorded prompt decisions when available. For Claude Code, local transcripts do not reliably distinguish a user-click accept from config, mode, or always-allow behavior; use OTEL tool_decision telemetry for click/source attribution. Secrets scan total: 1 hits across 3 targets; reported under Findings / Secrets Exposure.

/03 FINDINGS

6 findings across 3 categories.

Tabs are exposure categories. Use the filter to search across titles, samples, and tags. Per-hit secrets are grouped — full per-row evidence is in the appendix.

SeverityTitleEvidenceLast seenSample
criticalCodex sandbox bypass observed1n/asandbox=disabled
criticalGrok Build permission_mode is always-approve1n/apermission_mode=always-approve yolo=true
highClaude dangerous-mode confirmation prompt is disabled1n/askipDangerousModePermissionPrompt=true
SeverityTitleEvidenceLast seenSample
highPotential secret in chat export1n/aghp_****
mediumSecret-like value observed in chat export1n/aghp_****REDACTED****
SeverityTitleEvidenceLast seenSample
critical.env file found in git commit history1n/aproject#demo
/04 PERMISSIONS INVENTORY

Configured permission surface.

Settings-derived allow rules, MCP registrations, and observed approval decisions grouped by platform.

Claude Code

2 rules1 high1 critical
MCP Tooling
1
rule
Shell Execution
1
rule
Stored allow rules
1
non-MCP rules
Highest risk
critical
1 critical - 1 high - 1 medium

MCP servers and allowed tools

1 server - 1 scoped row
ServerScopeEvidenceSource
playwrightuser#abc123server registered-

Configured command allow rules

1 non-MCP allow rule
Recorded source
1 allow rule - user#abc123
Shell Execution 1
  • *
evidence/claude.json

Cursor

no persistent permission rules recorded

Cursor local permission state

mcp.json + state.vscdb + agent transcripts

The MCP table lists registrations from mcp.json plus project approvals. Known (runtime) counts servers Cursor has seen in state.vscdb; unmatched known servers have no local mcp.json row. Local state cannot reconstruct every clicked approval as a reusable command allow-list.

Registered MCP0
Approved project MCP0
Known MCP (runtime)0
Unmatched known0
Approval-like events0
Auto-accept workspaces0

Codex Desktop

1 rules0 high1 critical
General Tooling
1
rule
Stored allow rules
1
non-MCP rules
Highest risk
critical
1 critical - 0 high - 0 medium

Codex permission surface

1 non-MCP entries
Other config grants
1 entries - config.toml
  • prefix:demo
evidence/codex.json

GitHub Copilot

no persistent permission rules recorded

Grok Build

1 rules0 high1 critical
MCP Tooling
1
rule
Stored allow rules
0
non-MCP rules
Highest risk
critical
1 critical - 0 high - 1 medium

Grok Build local permission state

config.toml + sessions + events.jsonl

Inventory from config.toml, session summary/signals, and events.jsonl MCP resolution. Chat history and updates.jsonl content stay out of evidence. always-approve / yolo means tool use is not prompted.

Permission modealways-approve
Yoloyes
Sessions0
Messages0
Tool calls0
Transcript size0 B
Modelsnone
Prompt-history cwds0
Runtime MCP0
Config MCP1

MCP servers and allowed tools

1 server - 1 scoped row
ServerScopeEvidenceSource
demouser#mcp1server registered-
/05 CHAT EXPOSURE

Plaintext transcripts on the developer endpoint.

Transcript text stays in raw/. Only counts and retention metadata land here. The 90-day mark is the stated policy.

12
exported transcript files
0m
estimated active conversation time
1·files
transcript files with secret patterns · ≈ 8.3% of all transcripts
45·days
max retention · grok

Retention by tool · days held on disk

claude
45d
3 files - 0m active est.
codex
45d
2 files - 0m active est.
cursor
45d
4 files - 0m active est.
cursor composer
45d
2 files - 0m active est.
grok
45d
1 files - 0m active est.
▮ 90-day policy mark
ToolOldestNewestFilesActive estimateSecret-hit filesRetention
clauden/an/a30m045d
codexn/an/a20m045d
cursorn/an/a40m045d
cursor-composern/an/a20m045d
grokn/an/a10m045d

Active time is a capped-gap estimate from transcript timestamps: gaps between consecutive messages in the same session count up to 30 minutes. It is directional, not a timesheet, and tools with coarse timestamps may undercount.

/06 SECRETS & GIT POSTURE

Secret scanning and git posture.

gitleaks scans chat exports and repo roots for credential-shaped strings; samples are redacted and full hits stay in raw/secrets-scan/findings.csv. Git posture checks local repos for .env in history, hook presence, .gitignore coverage, and large blobs.

Secrets scan · 1 hits

No rule breakdown recorded.

// by location · chat: 0 · repos: 1
// scanner: gitleaks

Git posture · 5 repos

.env in history
1/ 5
pre-commit coverage
0%0 / 5
repos scanned
5
branch protection
not checked
(gh not enabled)
/07 METHODOLOGY & ATTESTATION

How the evidence was produced.

Collectors read local endpoint state and wrote evidence into this output directory. Raw evidence remains local; anything you share should follow the evidence contract in SCHEMA.md.

Collection scope

8 collectors produced local evidence. Collector versions and completion times are in Methodology.

CollectorStatusEvidence volume
Claude Codecollected2 permission rules
Cursorcollectedlocal state found
Codex Desktopcollected1 permission rules
GitHub Copilotcollectedsettings found
Grok Buildcollected1 permission rules
Chat Historycollected340 chat messages
Secrets Scancollected1 secret hits
Git Posturecollected5 git repos
CollectorWork performedCompleted atDurationVersionStatus
Chat transcripts
chat-history
Transcript export across detected AI tools2026-07-11 21:23:58 +0000not recorded1.0.0ok
Claude posture
claude
Claude settings, permissions, and MCP posture2026-07-11 21:23:58 +0000not recorded1.0.0ok
Codex posture
codex
Codex config, trusted projects, and MCP posture2026-07-11 21:23:58 +0000not recorded1.0.0ok
GitHub Copilot posture
copilot
Copilot local settings detection2026-07-11 21:23:58 +0000not recorded1.0.0ok
Cursor posture
cursor
Cursor local state, durable rules, and approval events2026-07-11 21:23:58 +0000not recorded1.0.0ok
Discovery
discovery
Local tool path and capability discovery2026-07-11 21:23:58 +0000not recorded1.0.0ok
Git posture
git-posture
Local repository hygiene checks2026-07-11 21:23:58 +0000not recorded1.0.0ok
Grok posture
grok
Grok config and session posture2026-07-11 21:23:58 +0000not recorded1.0.0ok
Secrets scan
secrets-scan
gitleaks scan over chat exports and repo roots2026-07-11 21:23:58 +0000not recorded1.0.0ok

Manifest SHA-256 (first 16 chars · full hashes in bundled manifest): manifest not pre

Raw evidence remains in the local output directory; shareable bundles should be sanitized per SCHEMA.md.

Demo Operator · 2026-07-11 18:36:02
/08 APPENDIX — EVIDENCE INDEX

Where to find the raw evidence behind each finding.

Per-hit gitleaks rows are aggregated by rule type. Identical findings collapse into a single row with a hit count; full per-row detail lives in the linked CSV.

Severity Finding Hits Evidence reference
critical.env file found in git commit history1evidence/git-posture.json
criticalCodex sandbox bypass observed1evidence/codex.json
criticalGrok Build permission_mode is always-approve1evidence/grok.json
highClaude dangerous-mode confirmation prompt is disabled1evidence/claude.json
highPotential secret in chat export1evidence/secrets-scan.json
mediumSecret-like value observed in chat export1evidence/chat-history.json