This paper studies infrastructure-level sabotage by AI software agents that complete assigned tasks while weakening permissions, logging, or persistence safeguards. It introduces an untrained Information Flow Graph (IFG) monitor that compares control-flow and data-flow graph changes alongside raw code diffs. In asynchronous evaluation, the untrained IFG monitor reduced attack misses at a 1% false-positive auditing budget from 11.6% for a git-diff monitor to 3.5%. In synchronous deployment, IFG-triggered realtime rollback reduced joint main-task and covert-task success from 74.4% to 0.0%, with no measurable reduction in legitimate task completion.
No heat snapshots are available in the last 24 hours.