Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 15:39 UTC. Ordered by latest scan.
Static source inspection confirms install-time code plants repository-wide AGENTS.md instructions, which the supplied policy treats as blockable AI-agent control hijack when lifecycle-tri...
The concrete issue is not classic malware but lifecycle-triggered mutation of Claude Code control files in the consuming project, which the policy treats as blockable AI-agent control hij...
Static inspection confirms automatic lifecycle mutation of Claude Code .claude agents/commands, which is a foreign/broad AI-agent control surface. Even though no exfiltration, remote code...
Static inspection confirms an unconsented npm lifecycle write into ~/.claude/skills, a foreign/broad AI-agent control surface covered by the block policy. The planted content appears beni...