Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 18:16 UTC. Ordered by latest scan.
The automatic global installation and use of third-party AI credential tooling is a concrete, unconsented install-time control-surface mutation. It meets the blocking policy for postinsta...
The package performs an unconsented postinstall write to a user's OpenCode configuration, causing a package-supplied plugin to load. This meets the install-time AI-agent control-surface m...
The published postinstall hook mutates foreign agent control surfaces, including OpenCode config, Hermes under the user home, and Cursor hooks, then reuses a local daemon bearer token to...
The automatic lifecycle hook writes package-controlled content into foreign global agent directories, meeting the install-control-surface blocking condition. The additional user-level pip...