Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 18:03 UTC. Ordered by latest scan.
The package automatically mutates consumer AI-agent configuration and instructions at install time. This is concrete install-hook abuse even though the inspected code does not directly ex...
The package uses an automatic postinstall path to persist instruction and command-hook behavior across detected AI-agent homes. The global-only guard does not provide user-command consent...
The package has a concrete automatic lifecycle chain that broadly mutates unrelated AI-agent skill locations and replaces existing content. This meets the install-hook abuse blocking policy.
The inspected source establishes an automatic postinstall chain that writes and merges global AI-agent configuration. This is concrete install-hook abuse under the stated policy.