Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 18:18 UTC. Ordered by latest scan.
Postinstall always writes Claude Code skill files under the user home, and after a prior setup marker it also rewrites Claude MCP and hook settings. That is unconsented install-time mutat...
The postinstall hook unconditionally mutates two foreign user-level agent skill directories, which is an unconsented broad AI-agent control-surface write. The same script also deletes non...
The postinstall hook writes Claude Code skills on every built install and, once local setup exists, also rewrites Claude MCP and settings hooks. That is unconsented lifecycle mutation of...
The postinstall hook unconsentingly rewrites foreign global AI-agent instruction files for Claude Code, Cursor, and Windsurf. That is a concrete control-surface hijack, not a user-invoked...