Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 12:47 UTC. Ordered by latest scan.
Source inspection confirms unconsented npm postinstall mutation of foreign/broad AI-agent control surfaces, which meets the block policy even though the MCP functionality itself appears p...
The package crosses the LPM block boundary because postinstall unconsentedly writes package-supplied AI-agent skills/agents/control files into foreign/broad IDE directories. Scanner simil...
Under the install control surface policy, unconsented npm postinstall mutation of foreign/broad AI-agent control surfaces is blockable even when the payload is package-aligned and no exfi...
Static inspection confirms automatic postinstall mutation of multiple broad AI-agent skill directories, matching the policy for blocking unconsented install-time mutation of foreign/broad...