Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:11 UTC. Ordered by latest scan.
The source establishes an automatic postinstall chain that downloads and executes a binary which writes a skill into shared AI-agent directories. This meets the install-time foreign AI-ag...
This is unconsented postinstall mutation of foreign AI-agent control surfaces and project skill metadata. The automatic lifecycle behavior is sufficient for a publish block even though no...
This is an automatic install-time mutation of a broad, foreign AI-agent control surface that creates persistent command execution. The conditional check for existing binaries does not pro...
The package automatically persists a launcher in Claude Desktop configuration during postinstall. This meets the policy for malicious install-hook abuse regardless of the Warp-branded API...