Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 09:12 UTC. Ordered by latest scan.
The concrete postinstall behavior satisfies the block policy regardless of scanner similarity labels. The lifecycle script writes outside the package and forcibly replaces foreign agent-c...
Source inspection confirms the lifecycle-driven global OpenCode configuration mutation; the scanner finding is substantiated. Although no exfiltration or remote code loading was found, th...
The lifecycle hook modifies global ~/.claude and ~/.codex control directories without a user command, meeting the blocking policy. The absence of a direct network call in the hook does no...
The package contains no observed exfiltration or remote code-loading chain, but its automatic postinstall installs and activates persistent global OpenCode control files. This meets the b...