# Our own additions to the bad-user-agents list — merged into the
# http-bad-ua parser by bin/gen-bad-ua.py after Mitchell Krogza's list
# (data/bad_user_agents.regex.txt, MIT, replaced whole by
# bin/update-data.sh; this file is ours and survives an update).
# One entry per line, in the same shape: a regex fragment, \b anchors,
# escaped spaces. For clients seen on our own hosts and not upstream
# yet — none at the moment: wp2shell (the REST-batch WordPress exploit
# tool of 2026-08) is upstream already, and the exploit tools that
# deserve an INSTANT ban are named in parsers/http-scanner-ua.yaml.
