Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 23:28 UTC. Ordered by latest scan.
This is concrete unconsented postinstall mutation of foreign/broad AI-agent control surfaces, meeting the blocking policy. Optional local-only MCP transport does not mitigate the install-...
The lifecycle script performs broad cross-vendor agent configuration and MCP registration without explicit user setup. Local-only networking and the apparent browser-automation purpose do...
The lifecycle hook performs persistent global Claude Code command installation, which meets the firewall block boundary for unconsented postinstall mutation of a foreign/broad AI-agent co...
The package performs unconsented postinstall mutation of a foreign AI-agent configuration and enables external agent control channels. This meets the firewall blocking boundary even thoug...