Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 04:08 UTC. Ordered by latest scan.
The automatic global postinstall mutates foreign AI-agent configuration and persists a provider and child agents. The global-install guard does not establish explicit consent for these ch...
The automatic postinstall hook silently writes consumer project AI-agent configuration and patches a third-party dependency. This meets the policy threshold for malicious install-hook abu...
The package's postinstall makes broad, persistent changes to a consuming project's agent, package lifecycle, and Git execution configuration. This is concrete unconsented install-time con...
The package's automatic postinstall both changes dependency-script policy and installs persistent AI-agent instructions into the consumer project. Its generated review exclusion conceals...