Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 20:14 UTC. Ordered by latest scan.
The package performs automatic postinstall AI-agent configuration rather than requiring an explicit user command. This meets the install-control-surface blocking policy.
The automatic lifecycle hook mutates a broad, foreign AI-agent control surface and installs instructions designed to suppress confirmation. This is concrete install-time control-surface a...
The package has a concrete automatic postinstall path that configures third-party AI coding clients through an executable it fetches and runs. The opt-out variables do not make the defaul...
The package performs unconsented postinstall mutation of foreign, broad AI-agent control surfaces, meeting the blocking lifecycle policy.