Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 11:33 UTC. Ordered by latest scan.
Direct inspection confirms an unconsented postinstall write to foreign, broad AI-agent control surfaces. This meets the blocking policy regardless of otherwise package-aligned browser aut...
This is concrete, unconsented postinstall mutation of a foreign and broad AI-agent control surface. The absence of observed exfiltration does not remove the install-time control-hijack be...
Direct source inspection confirms unconsented postinstall injection into both global agent skill locations. This meets the blocking policy regardless of the absence of credential exfiltra...
Source inspection confirms unconsented postinstall mutation of foreign project AI-agent control surfaces. This meets the block boundary regardless of benign-looking ancillary features and...