Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

Data exfiltration

Moving data out of a system to somewhere its owner did not intend.

For an agent, exfiltration rarely looks like a break-in. A tool is asked, by a sentence the model read somewhere, to put a file's contents in an argument, or to send a message to an address that is not the user's. The data leaves through a channel the agent was allowed to use.

That is why the pattern set on this site flags a tool description that names a destination, and why the rubric asks every listing to declare which hosts it contacts.

Why it matters

An agent with a mail tool, a file tool and a model that can be steered has everything needed to leak data without a single bug in any of them.

The mistake everyone makes

Looking for exfiltration as a network anomaly. It usually travels through a legitimate tool, to a legitimate service, in a legitimate-looking call.

Related terms

Egress allow-list
An explicit list of the hosts a piece of software is permitted to contact.
Prompt injection
Getting a model to follow instructions that arrive inside data it was asked to process.
Confused deputy
Tricking something that holds a privilege into using it for you.
Tool poisoning
Hiding instructions inside a tool description so the model reads them as commands.
Previous
CWE
Next
Dispute

See Data exfiltration on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue