Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 15:03 UTC. Ordered by latest scan.
Source inspection confirms install-time mutation of foreign/broad AI-agent MCP and instruction surfaces, which matches the firewall block policy even without observed exfiltration. The be...
Static inspection confirms install-time writes into foreign AI-agent MCP and instruction surfaces across workspace and user scopes. Although no exfiltration or destructive payload was fou...
The package crosses the firewall block boundary because postinstall mutates a foreign AI-agent/OAuth surface, even though the observed payload is branding-only and no credential exfiltrat...
The package performs unconsented postinstall mutation of a foreign dependency's OAuth control surface, which matches the blocking policy even though the observed payload is branding rathe...