Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:55 UTC. Ordered by latest scan.
The lifecycle hook creates and populates a consumer OpenCode configuration, including enabled npx-based MCP commands. That concrete automatic control-surface mutation meets the blocking p...
The package automatically injects enabled MCP commands into a consumer OpenCode workspace during postinstall. This is a concrete unconsented AI-agent control-surface mutation, so it meets...
This package deliberately disables and programmatically approves Claude Code safety controls, including a write to its global configuration. The behavior is concrete, automatic for sessio...
The package has a concrete automatic postinstall path that replaces skills across three user-home AI-agent control surfaces. The opt-out does not establish consent for the default install...