Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 22:50 UTC. Ordered by latest scan.
Direct inspection confirms a concrete postinstall-driven mutation of broad foreign AI-agent control surfaces. This meets the blocking policy regardless of the otherwise package-aligned op...
Direct source inspection confirms a postinstall hook deliberately disables a third-party agent's malware safety instruction. This meets the blocking policy for foreign AI-agent control-su...
The package has a concrete, install-time AI-agent control-surface mutation that installs automatic command execution. This meets the firewall block boundary despite its disclosed notifica...
Source inspection confirms a concrete npm postinstall chain that mutates Claude Code settings and installs event-triggered commands. This meets the blocking policy for unconsented postins...