Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 04:28 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of broad, pre-existing AI-agent control surfaces. The conditional checks and opt-outs do not establish user consent.
The package performs an automatic postinstall chain that alters consumer configuration and installs package-controlled AI-agent instructions and skills. Its generated instruction explicit...
This package has a concrete automatic postinstall chain that modifies and deletes files in a user's Claude Code configuration. The global-install trigger does not require a separate expli...
The postinstall hook mutates a foreign global agent control surface and installs an auto-starting background plugin. This is concrete unconsented install-hook abuse, even though no instal...