Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
The automatic lifecycle hook performs unconsented installation and configuration of a broad DSH AI-agent control surface. This meets the install-control-surface blocking boundary even wit...
The automatic post-install hook writes to a consumer-owned AI-agent control file, meeting the policy threshold for unconsented lifecycle mutation of a foreign control surface. No addition...
The package contains a concrete postinstall path that force-registers an agent skill in the user's global Muse scope. This is unconsented lifecycle mutation of a broad AI-agent control su...
This is concrete install-hook abuse: an automatic npm lifecycle hook changes multiple unrelated AI-agent configurations and installs a session-controlling plugin. The conditional director...