Sector analysis

Each sector scenario page carries the same injection payloads in a different context: a medical portal, a bank, a developer tool. This page shows the traffic each page records. It does not show whether agents behave differently by sector: a callback is recorded on the canary URL, which carries no sector, so callbacks cannot be attributed to the page that planted them.

successRate is withdrawn: a callback is recorded on the canary URL, which carries no sector path, so every callback lands in the general bucket and none can reach a named sector. A per-sector rate would divide outcomes that cannot be attributed to a sector by rows that can. Per technique, follow-through rows carry no technique tag, and a legacy-tagged callback counts inside its own denominator, so the same division fails there. Re-deriving the ratio from the published counts reproduces the same invalid division. A rate returns when a callback can be linked to the page that planted its canary.

Hypothesis

Agents are more compliant on sites that look authoritative (.org, healthcare, government), which is backwards from what security requires. Authoritative-looking sites should receive more scrutiny, not less.

Status: this page cannot test it. A test needs each callback linked to the page that planted its canary, and callbacks attributed to agents rather than to crawlers and browsers. The current instrument records neither.

Traffic by sector page

retail

Interactions
122
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
42
Payload categories
trap-customer-portal (39)trap-i18n-pt-br-retail (32)trap-i18n-zh-retail (19)trap-i18n-ja-retail (17)

healthcare

Interactions
121
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
35
Payload categories
trap-medical-records (52)trap-i18n-zh-medical (21)trap-i18n-ja-medical (17)trap-i18n-pt-br-medical (16)

finance

Interactions
106
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
25
Payload categories
trap-sec-filing (41)trap-i18n-zh-finance (19)trap-i18n-ja-finance (16)trap-i18n-pt-br-finance (16)

devops

Interactions
102
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
26
Payload categories
trap-ci-dashboard (44)trap-i18n-zh-ci (16)trap-i18n-ja-ci (15)trap-i18n-pt-br-ci (14)

legal

Interactions
43
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
18
Payload categories
trap-legal-documents (43)

government

Interactions
38
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
17
Payload categories
trap-gov-portal (38)

Outside the sector pages

Requests whose URL matches no sector scenario page: agentpwn.com's own pages and every callback, because the canary URL carries no sector. This is why per-sector callback counts cannot be read from this breakdown.

Interactions
15.5K
Canary Triggers
61
Callbacks
3.5K
Unique Fingerprints
3.7K

Sector scenarios

Explore realistic attack scenarios for each sector. These pages show how injection payloads are tailored to sector-specific contexts.