Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 17:21 UTC. Ordered by latest scan.
Although the package is otherwise transparent and lacks exfiltration or destructive behavior, the global postinstall hook performs an unconsented lifecycle write into Claude Code's skill...
Direct inspection confirms concrete AI-agent control-surface mutation: the installer writes Claude settings that bypass permission checks and expands trusted token-provisioning behavior....
Static inspection confirms unconsented lifecycle mutation of a host AI-agent control surface via postinstall, which is blocking behavior for the firewall even without credential theft or...
Static source inspection confirms unconsented lifecycle mutation of Codex/Claude agent skill and hook configuration, which is a concrete publish-block condition even though the CLI behavi...