Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
The automatic lifecycle chain modifies consumer package-manager configuration and agent instruction/capability locations. This meets the install-control-surface blocking policy despite no...
The automatic postinstall hook mutates a foreign, broad AI-agent control surface by installing command hooks. This meets the install-control-surface block policy.
An automatic postinstall invokes opaque setup that targets multiple AI-agent configuration surfaces. This is concrete unconsented install-time agent control-surface mutation.
The automatic lifecycle hook overwrites multiple AI-agent skill locations, including foreign product directories. This meets the install-control-surface block condition.