Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 06:37 UTC. Ordered by latest scan.
The package automatically installs unrestricted global Claude Code hooks rather than requiring an explicit user setup action. This meets the install-time AI-agent control-surface abuse bl...
This is a concrete unconsented postinstall mutation of a broad AI-agent control surface. The automatic lifecycle chain and persistent global command and instruction registration meet the...
This is unconsented postinstall mutation of broad foreign AI-agent control surfaces, including destructive replacement. The behavior meets the install-hook abuse blocking policy.
The package performs automatic postinstall AI-agent hook and configuration changes through an opaque executable. This is a concrete unconsented control-surface modification, not an explic...