Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 21:42 UTC. Ordered by latest scan.
The automatic postinstall hook directly modifies Claude Code configuration content and overwrites an existing skill installation. This meets the install-control-surface blocking policy ev...
Automatic installation persists a wildcard Claude Code command hook in the consumer project. This meets the blocking policy for unconsented postinstall mutation of a broad AI-agent contro...
The postinstall script writes command hooks into Claude Code's global settings file without asking the user. That is unconsented install-time mutation of a foreign AI-agent control surfac...
The postinstall hook mutates Claude Code and Codex MCP configuration without user consent, which is an unconsented install-time write to foreign AI-agent control surfaces. That is a block...