Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 01:28 UTC. Ordered by latest scan.
The automatic lifecycle hook mutates a global OpenCode agent configuration and deploys high-capability autonomous agent definitions. This is a concrete unconsented AI-agent control-surfac...
Automatic installation changes global Claude configuration to capture and export sensitive agent-session content. The opt-out environment variable does not establish prior user consent.
This is an unconsented postinstall mutation of a broad AI-agent control surface that enables remote collection of sensitive AI-session content. The behavior meets the install-hook abuse b...
The automatic postinstall mutates broad AI-agent skill directories for two unrelated agent environments and can remove existing destination content. This is unconsented install-time contr...