Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 00:46 UTC. Ordered by latest scan.
This is a cloned official Grok CLI wrapper published as @kingingwang/grok. Its postinstall automatically plants a native binary and config into ~/.grok, hijacking another vendor's Grok CL...
The postinstall script mutates Claude Code, Cursor, and Windsurf instruction files on install without user consent, which is unconsented foreign AI-agent control-surface hijack. Wallet se...
After npm install, this package writes its MCP server into Claude Code and Codex config files in the user home directory without asking. That is unconsented mutation of foreign agent conf...
Install-time postinstall auto-setup copies skill files into ~/.claude/skills/designcheck, which is Claude Code's control surface, without an explicit user setup command. That matches unco...