Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 17:14 UTC. Ordered by latest scan.
This is unconsented postinstall mutation of a broad foreign AI-agent control surface. CI and opt-out guards reduce exposure but do not make the default consumer-project modifications safe.
The automatic postinstall changes a consumer project's AI-agent plugin surface and refreshes remote plugin content. This is a concrete unconsented install-hook control-surface mutation.
Automatic installation changes the consumer project and injects agent-review controls that hide its own generated artifacts. This is concrete install-hook abuse, not a user-invoked setup...
This is an unconsented install-time mutation of a consumer AI control surface that captures and transmits application LLM content. The behavior is concrete and automatically reachable fro...