Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 09:05 UTC. Ordered by latest scan.
The package contains a concrete install-time chain that mutates both project-level agent state and user-wide Codex plugin state. That exceeds a package-local setup action and meets the bl...
The package's npm postinstall mutates broad, foreign AI-agent control surfaces and configures later hook execution. This meets the install-control-surface block criterion despite the abse...
The package performs unverified remote code execution during postinstall to install a separate Hermes AI agent. This is a concrete unconsented lifecycle mutation of a foreign AI-agent con...
Direct source inspection confirms unconsented postinstall mutation of both Claude and Codex global skill directories, including replacement of existing targets. The installed instructions...