Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 03:22 UTC. Ordered by latest scan.
This is an automatic postinstall mutation of broad, foreign AI-agent configuration and instruction surfaces. The injected skill also directs autonomous agent behavior, so it meets the pub...
The lifecycle path automatically launches runtime code that defaults to installing package-controlled hooks into external Claude workspaces. This is an unconsented postinstall AI-agent co...
The automatic postinstall mutates foreign AI-agent integrations and runs remotely obtained executable code. These unconsented install-time actions meet the blocking policy.
This is unconsented postinstall mutation of foreign AI-agent control surfaces, including a default Codex agent, combined with installed instructions that influence agent decisions. The gl...