Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 15:55 UTC. Ordered by latest scan.
The confirmed postinstall mutation of the host project's Cursor rules meets the blocking policy for an unconsented foreign AI-agent control-surface write. Other reviewed scripts do not mi...
The lifecycle script directly installs package-controlled instructions into the user's Claude skill directory. This meets the block threshold for unconsented postinstall mutation of a for...
The package performs concrete postinstall mutation of a consuming project's Claude Code configuration and extension directories. This meets the block boundary for unconsented install-time...
The lifecycle hook performs automatic, persistent writes to foreign Claude Code and Codex skill registries, which meets the install-time AI-agent control-surface hijack boundary. Detectio...