Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 03:45 UTC. Ordered by latest scan.
This is malicious install-hook abuse: an automatic lifecycle hook broadly alters foreign OpenCode/project state and global tooling, while runtime code reinforces the package's upgrade and...
This is concrete malicious install-hook abuse: an automatic lifecycle hook modifies consumer package-manager settings and broad AI-agent control surfaces while suppressing review and enco...
This package performs automatic postinstall mutation of foreign AI-agent control surfaces and installs additional user-level dependencies. That meets the install-hook abuse blocking crite...
This package performs an unconsented postinstall mutation of a foreign global AI-agent control surface. Its runtime server also exposes unauthenticated shell command forwarding on a non-l...