Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 00:46 UTC. Ordered by latest scan.
postinstall silently mutates the user's global Claude Code settings and turns on remote export of session prompts, replies, and tool traces. That is unconsented foreign agent-control-surf...
The automatic lifecycle hook mutates a foreign, broad AI-agent control surface and installs behavior-bearing commands. This meets the install-control-surface blocking policy despite the c...
This is a concrete unconsented postinstall mutation of foreign AI-agent configuration and hooks through an opaque native executable. That meets the install-control-surface blocking policy...
This is concrete install-time agent-control mutation, not merely an optional CLI feature. The opaque native payload and remote binary download make the resulting hook behavior unreviewabl...