AI Agents Can Now Be Monitored: Perplexity CEO Launches Open-Source Tool ‘Numbat’ to Detect Rogue Activity
- byPranay Jain
- 07 Sep, 2026
As AI agents become more powerful and gain access to more tools, files and systems, concerns about their security are also increasing. To address this emerging challenge, Perplexity CEO Aravind Srinivas has introduced an open-source security tool called Numbat.
The tool is designed to help security teams monitor what AI agents are doing, identify potentially suspicious behaviour and investigate incidents after they occur. Perplexity says that as autonomous AI systems become more capable, having a clear record of their actions will become increasingly important.
Rogue AI Agents Could Become a Security Challenge
Aravind Srinivas highlighted the growing concern around rogue AI agents in a post on X. He said that recent incidents involving agents escaping their sandboxes and interacting with third-party websites show why detecting malicious intent and conducting forensic investigations could become crucial.
Numbat has been introduced as an open-source tool that can help defenders gain greater visibility into AI-agent activity.
Numbat Tracks What AI Agents Are Doing
Numbat is designed to give users a detailed view of an AI agent's actions while it is running on a system.
The tool can work with supported desktop, command-line, IDE and gateway-based agents. It gathers information through local hooks and plugins and can also collect data from OTLP/HTTP logs and local session files.
This information can help security teams understand what an agent accessed, what actions it performed and what happened during a particular session.
It Can Flag Potentially Suspicious Behaviour
According to Perplexity, Numbat includes detection rules designed to identify a range of potentially dangerous activities.
These include:
-
Secret or credential theft
-
Data exfiltration
-
Command or code execution
-
Network reconnaissance
-
Privilege escalation
-
Lateral movement
-
Persistence
-
System tampering
The goal is not simply to record activity but to help security teams identify behaviour that may require investigation.
Create a Timeline of an AI Agent's Activities
One of Numbat's key features is its ability to create an activity timeline for an AI-agent session.
For example, if an agent begins scanning a network or performs another suspicious action, the activity can be flagged as a security finding. Investigators can then use the timeline to understand what happened before and after the event.
This type of visibility could be particularly useful when organisations need to determine whether an AI agent behaved unexpectedly or whether sensitive information may have been accessed.
Works Across macOS, Linux and Windows
Numbat is built using Go and is designed to run on macOS, Linux and Windows.
Users can run it as a standalone binary or install it through Go. Perplexity also says the tool can be deployed in enterprise environments using managed configurations and mobile device management (MDM) systems.
Why Tools Like Numbat Could Matter
AI agents are increasingly being given access to applications, files, databases, development environments and other tools. While this can make them highly useful, it also means that an agent behaving incorrectly—or being manipulated—could potentially create security problems.
Tools such as Numbat aim to provide organisations with the visibility needed to understand agent behaviour and investigate suspicious activity.
As AI agents become more autonomous, knowing what an AI system did may become just as important as knowing what it was asked to do.



