Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 04:28 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that mutates foreign and broad AI-agent control surfaces. This meets the install-hook abuse blocking policy despite no observed netw...
This is an unconsented postinstall mutation of a broad, foreign AI-agent control surface, combined with downloaded executable code and unsafe default permissions. The behavior is concrete...
The automatic lifecycle hook deletes and replaces third-party agent skill directories, then installs a skill with automatic global package installation behavior. This meets the install-ti...
This is concrete, unconsented postinstall mutation of a foreign AI-agent host and its user-level skill catalog. Backup and anchor checks limit breakage but do not remove the control-surfa...