Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 22:28 UTC. Ordered by latest scan.
After npm install, this package writes its MCP server into Claude Code and Codex config files in the user home directory without asking. That is unconsented mutation of foreign agent conf...
Install-time postinstall auto-setup copies skill files into ~/.claude/skills/designcheck, which is Claude Code's control surface, without an explicit user setup command. That matches unco...
The postinstall hook calls auto setup, which installs a Claude Code skill under the user home directory without an explicit user command. That is unconsented install-time mutation of a fo...
The published postinstall hook copies skill files into ~/.claude/skills, Claude Code's user-global agent control surface, without an explicit user command. That is unconsented install-tim...