Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 12:05 UTC. Ordered by latest scan.
Source inspection confirms the lifecycle hook injects a wildcard Claude Code hook into the consumer project, not merely first-party package configuration. The resulting handler processes...
Direct inspection confirms a concrete npm postinstall chain that modifies consumer-project MCP configuration and activates package code. Under the install-control-surface policy, this war...
Source inspection confirms a concrete postinstall AI-agent control-surface hijack and configurable data-upload behavior. The localhost default does not remove the risk because the hook is...
The package performs concrete install-time writes to the user's Claude skill directory and executes follow-on tooling. That meets the firewall block boundary for unconsented postinstall m...