Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 09:17 UTC. Ordered by latest scan.
The automatic postinstall hook writes into multiple foreign global AI-agent directories and installs remotely delivered executable code. That is concrete install-hook abuse under the stat...
The package has a concrete postinstall chain that automatically alters an MCP Chrome integration and invokes a permission-changing command. This meets the install-time foreign agent contr...
The automatic postinstall hook writes behavior-bearing instructions into the consuming project's CLAUDE.md. This is concrete install-hook abuse even though the inspected code does not sho...
The package performs a remote executable bootstrap during postinstall and automatically executes an opaque hook installer for AI-agent and editor integrations. That creates an unconsented...