Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:11 UTC. Ordered by latest scan.
The concrete, unconsented global postinstall overwrite of the codex AI-agent command is sufficient for blocking. No network exfiltration is needed for this control-surface hijack.
Direct source inspection confirms automatic writes into ~/.claude/skills and ~/.codex/skills, not merely a user-invoked setup command. This meets the install-time foreign AI-agent control...
The lifecycle hook performs broad AI-client configuration and executable MCP registration by default, rather than limiting setup to an explicit user command or a package-owned surface. No...
Source confirms an automatic postinstall write to global Claude Code configuration and executable command registration. That broad user-wide control-surface change meets the blocking poli...