Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 16:13 UTC. Ordered by latest scan.
The package performs an unconsented install-time write into ~/.claude/skills, a foreign AI-agent control surface, which matches the blockable AI-agent control hijack policy even though th...
Source inspection confirms install-time global Codex config mutation and remote MCP registration, matching the policy's blockable unconsented AI-agent control-surface write. The behavior...
The inspected source shows unconsented install-time mutation of ~/.claude/skills, a foreign AI-agent control surface covered by the block policy. Product-aligned content does not neutrali...
Static inspection confirms the scanner's critical finding: npm postinstall writes Claude skills and MCP registrations into user-level Claude control surfaces. Under the provided install-c...