Sector analysis

Each sector scenario page carries the same injection payloads in a different context: a medical portal, a bank, a developer tool. This page shows the traffic each page records. It does not show whether agents behave differently by sector: a callback is recorded on the canary URL, which carries no sector, so callbacks cannot be attributed to the page that planted them.

successRate is withdrawn: a callback is recorded on the canary URL, which carries no sector path, so every callback lands in the general bucket and none can reach a named sector. A per-sector rate would divide outcomes that cannot be attributed to a sector by rows that can. Per technique, follow-through rows carry no technique tag, and a legacy-tagged callback counts inside its own denominator, so the same division fails there. Re-deriving the ratio from the published counts reproduces the same invalid division. A rate returns when a callback can be linked to the page that planted its canary.

Hypothesis

Agents are more compliant on sites that look authoritative (.org, healthcare, government), which is backwards from what security requires. Authoritative-looking sites should receive more scrutiny, not less.

Status: this page cannot test it. A test needs each callback linked to the page that planted its canary, and callbacks attributed to agents rather than to crawlers and browsers. The current instrument records neither.

Traffic by sector page

healthcare

Interactions
116
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
34
Payload categories
trap-medical-records (52)trap-i18n-zh-medical (20)trap-i18n-ja-medical (15)trap-i18n-pt-br-medical (15)

retail

Interactions
110
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
34
Payload categories
trap-customer-portal (37)trap-i18n-pt-br-retail (26)trap-i18n-zh-retail (18)trap-i18n-ja-retail (15)

finance

Interactions
101
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
24
Payload categories
trap-sec-filing (40)trap-i18n-zh-finance (18)trap-i18n-ja-finance (15)trap-i18n-pt-br-finance (15)

devops

Interactions
98
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
25
Payload categories
trap-ci-dashboard (43)trap-i18n-zh-ci (15)trap-i18n-ja-ci (14)trap-i18n-pt-br-ci (14)

legal

Interactions
41
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
16
Payload categories
trap-legal-documents (41)

government

Interactions
37
Callbacks
not attributable
Canary Triggers
not attributable
Unique Fingerprints
16
Payload categories
trap-gov-portal (37)

Outside the sector pages

Requests whose URL matches no sector scenario page: agentpwn.com's own pages and every callback, because the canary URL carries no sector. This is why per-sector callback counts cannot be read from this breakdown.

Interactions
14.1K
Canary Triggers
61
Callbacks
3.2K
Unique Fingerprints
3.3K

Sector scenarios

Explore realistic attack scenarios for each sector. These pages show how injection payloads are tailored to sector-specific contexts.