Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 11:03 UTC. Ordered by latest scan.
Source inspection confirms a concrete lifecycle-triggered remote payload write into Claude Code, Codex, and OpenClaw directories. This meets the blocking policy regardless of the package'...
The package contains a concrete, unconsented postinstall mutation of foreign project AI-agent instruction files. Benign UI bundle contents do not mitigate this lifecycle control-surface h...
Source inspection confirms a real postinstall chain that automatically installs agent skills across multiple host AI-tool directories. Documentation and prefix-scoped cleanup reduce ambig...
The concrete postinstall behavior mutates broad, foreign AI-agent skill directories. This meets the block boundary even though the inspected installer path showed no network exfiltration.