Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 14:28 UTC. Ordered by latest scan.
Static inspection confirms unconsented postinstall mutation of OpenCode global config and AGENTS.md, which meets the firewall block policy for AI-agent control-surface writes. Other risky...
Source inspection confirms install-time mutation of broad AI-agent control surfaces through a postinstall hook, which meets the block policy. The scanner finding is substantiated by packa...
This matches the firewall block policy for unconsented npm postinstall mutation of a foreign/broad AI-agent control surface. The behavior is package-aligned and mostly local, but the inst...
The reviewed JS wrapper has no direct exfiltration or payload obfuscation, but its lifecycle hook automatically triggers documented agent/daemon setup. Under the install control surface p...