Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:09 UTC. Ordered by latest scan.
The automatic postinstall fan-out mutates several home-directory AI-agent extension and configuration surfaces and may run a project upgrade. This concrete install-time behavior meets the...
The package automatically mutates a foreign AI-agent control surface during postinstall, which meets the install-control-surface blocking policy. Its runtime self-upgrade further makes th...
This is an automatic postinstall mutation of foreign project and machine AI-agent control surfaces, not an explicit setup command. The absence of demonstrated exfiltration does not neutra...
The package has a concrete automatic postinstall path that mutates multiple consumer-project AI-agent control surfaces. This meets the install-control-surface blocking rule despite the ab...