Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 21:57 UTC. Ordered by latest scan.
Source inspection confirms automatic postinstall mutation of consumer project and Claude Code plugin state, including marketplace refresh and third-party plugin installation. This meets t...
The automatic postinstall hook modifies multiple external AI-agent instruction files and injects behavioral guidance. This meets the policy definition of malicious install-hook abuse.
This package performs an automatic postinstall mutation of several foreign AI-agent control surfaces and injects instructions for financial and credential-related actions. This meets the...
The automatic lifecycle chain silently mutates global instruction surfaces for multiple AI-agent products. This meets the install-control-surface blocking policy regardless of the absence...