Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 17:43 UTC. Ordered by latest scan.
The package has a concrete install-time AI-agent control-surface write into the consuming project. No separate network or credential-theft behavior was found, but the unconsented postinst...
This is a concrete, unconsented postinstall mutation of broad foreign AI-agent control surfaces, which meets the blocking policy. No network exfiltration is needed for the control-hijack...
The package has a concrete, unconsented postinstall chain that mutates multiple foreign AI-agent control surfaces and may overwrite existing skill files. This meets the blocking policy re...
The lifecycle code concretely installs, executes, and patches a separate AI-agent package during npm installation. This meets the blocking policy for unconsented postinstall mutation of a...