Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 08:07 UTC. Ordered by latest scan.
The package has a concrete postinstall chain that installs agent skills globally across detected hosts without an explicit user command. This meets the firewall block policy for foreign/b...
The package performs unconsented postinstall mutation of a broad, user-level OpenCode command surface. This concrete lifecycle control-surface write meets the blocking policy even though...
The package performs the policy-defined blocking behavior directly at npm postinstall: broad AI-agent configuration mutation without an explicit user command.
The concrete unconsented postinstall mutation of broad AI-agent control surfaces meets the firewall block policy. Branding and visible error handling do not remove that install-time contr...