Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 08:31 UTC. Ordered by latest scan.
The package performs automatic postinstall mutation of consumer lifecycle and AI-agent configuration, including third-party plugin installation. This is a concrete install-hook abuse path...
This is concrete install-time AI-agent control-surface mutation, not merely a user-invoked setup command. The global-install guard does not make the automatic cross-product configuration...
The package contains reviewer and AI-directed verdict-control text in its MCP implementation. Although it lacks an npm install hook, this is a concrete agent-control attack surface when i...
The automatic lifecycle chain writes into a broad global AI-agent control surface. Its scoped filenames and lack of confirmed exfiltration reduce the apparent payload severity, but they d...