Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 00:20 UTC. Ordered by latest scan.
This is a concrete unconsented postinstall mutation of a consumer OpenCode control surface, coupled with remote vendor-controlled content application. Signature verification does not remo...
The automatic postinstall writes enabled agent-control configuration and a broad set of agent content into the consuming project. Existing-file conflict handling does not provide consent...
This is an unconsented install-time mutation of broad Claude and Codex command control surfaces, combined with persistent scheduled self-updating. The global-install guard does not make t...
The automatic postinstall hook modifies four global AI-agent skill roots and enables implicit agent behavior. This meets the policy definition of malicious install-hook abuse despite no v...