Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 16:46 UTC. Ordered by latest scan.
The postinstall hook writes Claude Code skill files on every install and, after a prior setup marker, also rewrites Claude hook settings and MCP config. That is unconsented install-time m...
The package performs remote code execution and foreign git-ai configuration mutation automatically from postinstall. This meets the install-control-surface blocking condition.
The automatic lifecycle hook mutates foreign, broad AI-agent configuration surfaces without consent. This meets the policy threshold for blocking install-hook-based AI-agent control hijac...
The postinstall hook unconditionally mutates Claude Code and Codex global MCP configuration to launch this package's server, which is an unconsented install-time write to foreign agent co...