Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 10:48 UTC. Ordered by latest scan.
This is unconsented postinstall mutation of a broad, foreign AI-agent control surface. No data theft was confirmed, but the automatic persistent agent-control changes meet the publish-blo...
This is an automatic postinstall path that invokes an opaque native binary to reconcile AI-client hooks and state. That is a concrete unconsented lifecycle mutation of a foreign AI-agent...
This package automatically mutates a foreign AI-agent control surface during postinstall and supplies a launcher that enables unrestricted permissions and changes user agent configuration...
The automatic postinstall hook silently delegates to an opaque native binary to modify several foreign coding-agent skill directories. This meets the install-control-surface block policy.