Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 09:59 UTC. Ordered by latest scan.
The package uses an automatic npm lifecycle hook to copy package-controlled skill content into shared and third-party AI-agent directories. This meets the install-time AI-agent control-su...
This is an automatic postinstall mutation of user-level Claude configuration that establishes ongoing command execution. The behavior meets the install-control-surface block policy despit...
The inspected source establishes an automatic npm lifecycle chain that writes third-party agent configuration and rules, producing persistent automatic package execution. This meets the i...
This is concrete install-hook abuse: an automatic npm lifecycle script modifies global Claude settings and installs recurring command hooks without user confirmation. The absence of netwo...