Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 08:41 UTC. Ordered by latest scan.
Source inspection confirms the lifecycle hook mutates a third-party AI-agent package. Under the install-control-surface policy, this warrants blocking even though the patch is narrow and...
The package has a concrete unconsented postinstall mutation chain targeting broad third-party AI-agent control surfaces. The absence of install-time networking does not mitigate that pers...
This is concrete, unconsented postinstall mutation of foreign global AI-agent control surfaces, including a persistent Codex lifecycle execution hook. The absence of install-time network...
Source inspection confirms the lifecycle installer performs broad foreign AI-agent configuration writes. This meets the blocking policy regardless of the absence of network exfiltration.