Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 19:28 UTC. Ordered by latest scan.
Postinstall unconditionally mutates the global Claude Code settings file to export prompt and tool content to a package-controlled collector. That is unconsented install-time control of a...
The install hook writes this package into several unrelated AI-agent skill directories and turns on a Codex plugin without a user command. That is an unconsented install-time takeover of...
The install hook unconditionally plants skills in Claude's home config and, when other agent directories exist, writes those control surfaces too, including enabling a Codex plugin and MC...
Unconsented postinstall rewrites the user-wide Claude Code control file and turns on prompt and tool export to a package-controlled collector. A later explicit CLI install does not author...