Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 04:55 UTC. Ordered by latest scan.
The package automatically mutates Claude Code's user-level skills directory through an obfuscated postinstall payload. This meets the install-hook policy for an unconsented foreign AI-age...
This is a concrete unconsented postinstall mutation of broad AI-agent control surfaces in the consumer project, compounded by changes intended to ensure future lifecycle execution. The ab...
The automatic postinstall hook modifies several foreign AI-agent control surfaces and installs activating instructions into each. This is concrete unconsented install-time agent-control m...
The package performs automatic postinstall registration of an external Chrome MCP bridge and permission changes. That is a concrete unconsented AI-agent control-surface mutation.