Introducing Zorro Security / A new perspective on AI security ↗
zorroSECURITYSign in Build with us ↗

USE CASES

Start with the incident.
Then the pattern.

Nine scenarios. Six are anchored to a documented breach; three describe the workforce pattern behind an ordinary week. Each shows the capability that answers it and whether that capability is measured or structurally positioned.

APPSEC · CI/CD

A review agent that runs on every pull request

THE INCIDENTComment and Control: PR titles, issue bodies and hidden HTML comments made three vendors’ review agents post their own CI secrets back through GitHub. CSA research note ↗

THE ANSWERThe hook decides each action against authority the session still holds, so untrusted contributor content cannot steer the agent into reading secrets it was never granted. The decision runs without prompts in unattended CI.

STRUCTURAL

SUPPLY CHAIN

A dependency that arrives with instructions

THE INCIDENTCamoLeak (CVE-2025-59145) routed Copilot Chat’s exfiltration through GitHub’s image proxy; the Cline triage-bot injection stole npm tokens and published a malicious package to ~4,000 developers. Case studies ↗

THE ANSWEROrigin sets derived from the committed HEAD make allowed hosts and packages a membership test, and lookalike detection flags near-miss destinations. A package outside the manifest asks rather than installs.

STRUCTURAL

ZERO-CLICK EXFILTRATION

An email, a PDF, a calendar invite

THE INCIDENTEchoLeak (CVE-2025-32711) exfiltrated mailbox data from a single crafted email; Notion’s AI was steered by a malicious PDF; a poisoned calendar invite leaked meeting details. EchoLeak paper ↗

THE ANSWERUntrusted content lowers the session’s authority when it arrives, not when a model reads it. Whatever an injected object says, it can only make the agent ask more. It cannot widen what it may reach.

STRUCTURAL

MCP & TOOL SUPPLY CHAIN

A tool description you never read

THE INCIDENTTool poisoning hides instructions in MCP tool descriptions; a protocol-level flaw runs commands even on error across thousands of exposed servers; the Amazon Q extension was told to wipe S3. Microsoft on tool poisoning ↗

THE ANSWEREvery MCP tool definition is pinned before it is forwarded: a hash of name, description, schema and server identity. A definition that changed since a person approved it voids the grant.

STRUCTURAL

NON-HUMAN IDENTITY

Raw credentials in the agent’s environment

THE INCIDENTInjected agents dump environment variables and .env files; the credential broker removes the raw secret from the environment entirely. Measured result ↗

THE ANSWERThe broker replaces credentials with ephemeral, scoped tokens that are worthless off the host and after the broker stops. Measured on macOS: 0 of 9 leak vectors succeeded under the broker, vs 6 of 8 without it.

MEASURED

CONTAINMENT

An agent that deletes what it shouldn’t

THE INCIDENTPocketOS lost its production database and backups in nine seconds; Replit’s agent hid a deletion; a Gemini run purged 28,745 lines and fabricated a recovery; an agent loop cost $47,000 over eleven days. Case studies ↗

THE ANSWERA kill switch that acts before the next action: revoking a session turns its next tool call into a denial. Containment lives at the point of decision, not in the transcript afterwards.

STRUCTURAL

INHERITED PERMISSIONS

An agent that reaches what its owner never opened

THE PATTERNAn agent runs with a person’s permissions, not its own. Everything that person could reach, it can reach, and it reaches it in one session rather than over a career. OWASP names the class: excessive functionality, permissions and autonomy. OWASP on excessive agency ↗

THE ANSWERThe workforce graph holds the person, the agent, the session and the resource, so reach is a path you can read rather than an assumption you carry. The exposure profile resolves what an agent can reach from what it was actually delegated, and the rollout simulator refuses to call a deployment safe on insufficient data.

STRUCTURAL

ACCESS RIGHT-SIZING

A departing employee whose access was never right-sized

THE PATTERNEntitlements accumulate. A person changes team twice, keeps both sets, and leaves with access nobody re-examined. The distance between what was granted and what was ever used is where an offboarding goes wrong. Identity & access ↗

THE ANSWERRight-sizing compares granted entitlements against observed use and reports the difference; posture detection surfaces dormant accounts and standing admin. The lifecycle around the fix is real and strict: a model may propose, a model subject can never approve, and closure is re-observed rather than declared. The effector is not. Execution revokes a session; an entitlement recommendation is marked applied, not changed at the provider, because there is no connector to act through.

STRUCTURAL

STALE SHARES

A share still live years after anyone read it

THE PATTERNA link created for one review outlives the review. Public and anonymous links, shares to an external domain, and documents nobody has opened in years are the quiet half of data exposure. Data exposure ↗

THE ANSWERExposure scanning evaluates which shares actually expose an asset rather than which ones merely exist, and a what-breaks analysis says what stops working if the share is removed. That turns a revocation into a decision instead of a gamble. Removing it is still a human act in the provider: there is no revoke-share effector, and the finding is marked for re-observation rather than closed on the strength of an intention.

STRUCTURAL

Structural is not
the same as measured.

The authority model (monotone attenuation, origin sets from HEAD, membership instead of score) is a position about architecture, not a claimed detection rate. Where a number has been measured against real binaries, it is labeled MEASURED; where a capability is how the architecture is built, it is labeled STRUCTURAL. Neither is a prevention rate until it is run on a pinned benchmark. The three cases labeled THE PATTERN are answered by services that sit in the middle of the loop, so they are bounded at both ends: nothing is ingested agentlessly from an identity provider or a drive today, and execution has one effector. Each of those cases says so in its own answer rather than leaving it to a footnote.

See the loop and where it breaks ↗

YOUR REALITY FIRST

Bring us the incident
that worries you.

Define the scope before connecting an environment. The right pilot has a clear source, an agreed outcome and evidence both teams can inspect.

Define your first use case ↗