Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 12:46 UTC. Ordered by latest scan.
The source establishes a concrete install-time foreign AI-agent control-surface write and startup persistence chain. Lack of outbound traffic in the inspected plugin does not negate the p...
The inspected postinstall behavior concretely mutates foreign host AI-agent configuration and installs plugins automatically. This exceeds a first-party, user-invoked setup flow.
This is a concrete npm-postinstall mutation of a foreign, user-global AI-agent control surface. Conditional harness selection and tagged merging reduce scope but do not make the lifecycle...
This is unconsented postinstall mutation of foreign AI-agent control surfaces, meeting the block policy. Obfuscation and additional dependency rewriting raise confidence; no exfiltration...