Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 17:33 UTC. Ordered by latest scan.
The postinstall hook unconditionally mutates two foreign user-level agent skill directories, which is an unconsented broad AI-agent control-surface write. The same script also deletes non...
The postinstall hook writes Claude Code skills on every built install and, once local setup exists, also rewrites Claude MCP and settings hooks. That is unconsented lifecycle mutation of...
The postinstall hook unconsentingly rewrites foreign global AI-agent instruction files for Claude Code, Cursor, and Windsurf. That is a concrete control-surface hijack, not a user-invoked...
The package performs unconsented postinstall mutation of a consumer OpenCode control surface and installs remotely supplied content into it. This is a concrete install-hook abuse path des...