Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 12:33 UTC. Ordered by latest scan.
Source proves unconsented postinstall mutation of a user-wide AI-agent control surface, which meets the blocking policy. The package-aligned collector and opt-out do not neutralize the au...
Source proves unconsented postinstall mutation of a global AI-agent instruction surface, which meets the supplied blocking policy. Package ownership and partial plugin guards do not preve...
The inspected lifecycle chain performs unconsented install-time mutation of a broad AI-agent control surface, meeting the supplied blocking policy. The separate guarded runtime integratio...
The inspected lifecycle path performs unconsented mutation of foreign, global AI-agent control surfaces. This meets the blocking policy despite the package ownership of the installed skil...