Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 06:59 UTC. Ordered by latest scan.
The automatic postinstall hook overwrites a global AI-agent instruction file under the user's home directory. This meets the policy boundary for malicious install-time AI-agent control-su...
Source inspection confirms an unconsented postinstall mutation of a broad AI-agent control surface via an external installer. This meets the install-control-surface block policy.
The guarded global trigger does not make the lifecycle mutation consented: installation automatically rewrites broad shell and agent command surfaces and adds persistence. This meets the...
The automatic lifecycle path mutates both Claude hooks and global Codex trust configuration. This is an unconsented install-time change to AI-agent control surfaces.