Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 18:22 UTC. Ordered by latest scan.
Source confirms an unguarded npm postinstall mutates Claude Code configuration in the consumer project and runs pip installation. This meets the install-control-surface block policy despi...
The postinstall creates a foreign, global Claude Code control surface rather than limiting setup to an explicit CLI command or the target project. This meets the blocking policy despite n...
Concrete lifecycle code modifies global ~/.claude settings and installs a command invoked by all Claude Code sessions. No network exfiltration is needed for this policy-defined install-ti...
This is unconsented postinstall mutation of a foreign, user-wide AI-agent control surface. The absence of observed exfiltration does not remove the concrete persistent control-surface imp...