Sector analysis
Each sector scenario page carries the same injection payloads in a different context: a medical portal, a bank, a developer tool. This page shows the traffic each page records. It does not show whether agents behave differently by sector: a callback is recorded on the canary URL, which carries no sector, so callbacks cannot be attributed to the page that planted them.
successRate is withdrawn: a callback is recorded on the canary URL, which carries no sector path, so every callback lands in the general bucket and none can reach a named sector. A per-sector rate would divide outcomes that cannot be attributed to a sector by rows that can. Per technique, follow-through rows carry no technique tag, and a legacy-tagged callback counts inside its own denominator, so the same division fails there. Re-deriving the ratio from the published counts reproduces the same invalid division. A rate returns when a callback can be linked to the page that planted its canary.
Hypothesis
Agents are more compliant on sites that look authoritative (.org, healthcare, government), which is backwards from what security requires. Authoritative-looking sites should receive more scrutiny, not less.
Status: this page cannot test it. A test needs each callback linked to the page that planted its canary, and callbacks attributed to agents rather than to crawlers and browsers. The current instrument records neither.
Traffic by sector page
healthcare
retail
finance
devops
legal
government
Outside the sector pages
Requests whose URL matches no sector scenario page: agentpwn.com's own pages and every callback, because the canary URL carries no sector. This is why per-sector callback counts cannot be read from this breakdown.
Sector scenarios
Explore realistic attack scenarios for each sector. These pages show how injection payloads are tailored to sector-specific contexts.