Traces
Forensic audit trail of all agent actions
Datadog-style query. Fields:
agent, tool, risk, status, @args.X, free-text "phrase". AND / OR / NOT / parens.15 / 15
POSTed api.openai.com
Aug 11, 2026 at 10:06 PM312ms
Emailed alice.chen@gmail.com
Aug 11, 2026 at 10:04 PM220ms
Wrote /root/.ssh/id_rsa
Aug 11, 2026 at 10:01 PM12ms
BLOCKED by policy `no-privileged-file-access` — `/root/.ssh/*` is on the read-only allowlist for non-root agents.
Queried users
Aug 11, 2026 at 9:59 PM47ms
POSTed api.github.com
Aug 11, 2026 at 9:56 PM398ms
Emailed crypto-airdrop@gmail.com
Aug 11, 2026 at 9:54 PM188ms
BLOCKED by policy `block-personal-email-in-checkout` — recipient `*@gmail.com` denied for the checkout workflow; allow-list is `*@acme.io`.
POSTed api.stripe.com
Aug 11, 2026 at 9:52 PM285ms
POSTed api.vercel.com
Aug 11, 2026 at 9:50 PM412ms
POSTed api.linear.app
Aug 11, 2026 at 9:46 PM195ms
POSTed api.datadoghq.com
Aug 11, 2026 at 9:42 PM268ms
POSTed api.anthropic.com
Aug 11, 2026 at 9:37 PM542ms
Wrote /data/exports/q2.json
Aug 11, 2026 at 9:33 PM16ms
POSTed api.sendgrid.com
Aug 11, 2026 at 9:27 PM232ms
Searched Google for "CVE-2026-31337 affected versi…"
Aug 11, 2026 at 9:22 PM480ms
POSTed api.cloudflare.com
Aug 11, 2026 at 9:16 PM174ms