Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 11:30 UTC. Ordered by latest scan.
This is an automatic postinstall mutation of a broad AI-agent control surface, not an explicit user-command setup. The recurring hooks and global instruction writes establish concrete per...
This is a concrete unconsented postinstall mutation of global Claude Code configuration and instructions. The package's registry update check does not mitigate the lifecycle control-surfa...
The package automatically persists package-controlled instructions into multiple unrelated AI-agent skill directories during installation and runtime. The opt-out does not make this an ex...
This is an unconsented postinstall mutation of broad AI-agent control surfaces. The forced global installation makes the behavior concrete and block-worthy.