Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 05:11 UTC. Ordered by latest scan.
The automatic postinstall hook forcefully mutates multiple foreign AI-agent skill locations, which is concrete install-time control-surface abuse. The absence of demonstrated exfiltration...
The automatic lifecycle hook overwrites foreign AI-agent skill directories by default, which is concrete control-surface hijacking. The later automatic global npm install increases the pe...
Automatic postinstall execution of an opaque native hook installer is an unconsented AI-agent control-surface mutation. The visible JavaScript confirms the lifecycle chain even though the...
The automatic lifecycle path materially changes consumer AI-agent settings and hooks, rather than limiting setup to an explicit user command. This meets the policy threshold for a publish...