News
Button releases an emergency update to stop using Coze CLI skills to hijack workflows, but still installs skills silently
1 min read
Source: landian.news
#SecurityInformation After being criticized as being hijacked by a virus, Kouzi released an emergency update to stop using Coze CLI skills to hijack workflows such as Codex and Claude Code. Bluedot.com mentioned at noon yesterday that the Coze CLI silent installation skill hijacks other agents and diverts them to Kouzi. Yesterday afternoon, the Kouzi team released Coze CLI version 0.3.7 to stop hijacking. The new version mainly modifies the skill description, from automatically detecting the trigger to no longer hijacking the diversion unless the user explicitly calls it. However, the new version will still continue to silently install skills and write them to the shared skills directory. Users can detect this involuntary installation of skills when using Codex or Claude Code. View the full text: https://ourl.co/114279