Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 20:24 UTC. Ordered by latest scan.
The automatic lifecycle hook installs a bundled skill globally across a broad set of foreign AI-agent integrations without explicit user action. This is concrete install-hook abuse of an...
This package performs an unconsented postinstall mutation of broad third-party AI-agent skill locations. Conflict checks reduce accidental overwrites but do not remove the automatic contr...
The package has no observed exfiltration or remote execution, but its automatic postinstall writes behavior-bearing content into two foreign user-level agent skill roots. This meets the i...
The source establishes an unconsented postinstall mutation of broad, foreign AI-agent control surfaces. No network or secret theft is needed for this install-hook abuse to warrant blocking.