Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 18:49 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that overwrites a foreign AI-agent executable with opaque payloads. That meets the install-control-surface blocking policy despite b...
The automatic lifecycle hook modifies a consumer-owned MCP configuration rather than only package-owned files. That creates an unconsented agent-extension execution path.
The package has a concrete automatic postinstall chain that overwrites skill content in Claude, agent, and Codex directories. Opt-out support does not establish consent for the default mu...
This is an unconsented postinstall mutation of broad AI-agent control surfaces in the consumer project. The automatic configuration includes remote MCP endpoints and a command launcher.