Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 17:07 UTC. Ordered by latest scan.
This meets the install-control-surface block criterion: unconsented postinstall mutation of broad foreign AI-agent configurations. Runtime provider networking appears feature-aligned and...
Direct source inspection confirms automatic cross-platform agent configuration writes plus Claude Code permission expansion during postinstall. This meets the install-control-surface bloc...
The package has a concrete install-time chain that silently modifies ~/.claude/settings.json and registers execution hooks. This meets the block policy for unconsented postinstall mutatio...
The package performs concrete automatic postinstall writes to Claude Code's global configuration and overrides its status line. Guard conditions and an npm update check do not remove that...