Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 20:21 UTC. Ordered by latest scan.
The lifecycle hook creates persistent, cross-client agent-control changes during installation, meeting the blocking policy. No network exfiltration is needed for this concrete control-sur...
This is concrete, unconsented postinstall mutation of a broad foreign AI-agent configuration surface. It meets the firewall block criterion regardless of otherwise normal CLI and bundled-...
Source confirms an unconsented postinstall mutation of a broad, foreign AI-agent control surface. This meets the install-control-surface block boundary regardless of the optional opt-out...
Source inspection confirms concrete automatic mutation of ~/.agents/skills through a postinstall hook. This meets the blocking policy for unconsented postinstall changes to a foreign/broa...