Exploitation of AI Agent Framework Endpoint Leading to Code Execution

Detects anomalous, high-volume HTTP requests to AI agent orchestration endpoints (e.g., tool invocation, plugins, or webhooks) followed by suspicious process execution or outbound network connections from the same host. This behavior is indicative of RCE exploitation against an AI agent framework, such as insecure deserialization or SSRF within a plugin connector.