Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 07:34 UTC. Ordered by latest scan.
This is malicious because an install-time hook modifies broad downstream AI-agent controls and deploys instructions that encourage credential exposure while suppressing security review.
Direct inspection confirms unconsented postinstall mutation of broad, foreign AI-agent control surfaces. This meets the blocking policy even though no network exfiltration was found in th...
This is an unconsented postinstall mutation of broad, foreign AI-agent control surfaces. The local-only copy and integrity check do not remove that install-time control hijack.
The install-time remote archive is not pinned independently, and its content is used to populate global Claude Code skills with remotely controlled names. This is an unconsented broad AI-...