Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
The active postinstall chain performs unconsented broad deletion within a foreign AI agent control surface. This meets the blocking policy regardless of the legacy-cleanup explanation.
Inspected source establishes unconsented postinstall mutation of a global AI-agent instruction file. This meets the supplied blocking policy independently of citation coverage or any unpr...
Source proves unconsented postinstall mutation of Claude's global agent control surface, which meets the specified blocking policy. The separate interactive init command does not authoriz...
The inspected lifecycle chain performs unconsented installation-time mutation of broad AI-agent control surfaces, meeting the supplied blocking policy. This conclusion rests on executable...