Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
An automatic postinstall invokes opaque setup that targets multiple AI-agent configuration surfaces. This is concrete unconsented install-time agent control-surface mutation.
The automatic lifecycle hook overwrites multiple AI-agent skill locations, including foreign product directories. This meets the install-control-surface block condition.
The package has a concrete automatic lifecycle hook that force-replaces skill directories for several unrelated AI-agent environments. This meets the install-control-surface blocking poli...
The automatic lifecycle hook changes an AI-agent plugin configuration outside an explicit user setup action. Its home-level configuration targeting makes the mutation a broad control-surf...