Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The automatic postinstall mutates user-level Codex and Claude agent skill directories and prunes their contents. This is an unconsented install-time change to AI-agent control surfaces, s...
The npm postinstall automatically mutates installed agent integrations and invokes native logic that repairs Codex hooks, establishing unconsented install-time control-surface changes. Th...
The source establishes automatic, unguarded writes to OpenCode's shared agent control surface, meeting the explicit blocking rule. Ordinary workflow content and the absence of exfiltratio...
The source establishes unconsented postinstall mutation of a foreign, global AI-agent control surface, meeting the explicit blocking rule. Ordinary development prompts and absent exfiltra...