Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 06:36 UTC. Ordered by latest scan.
This is an unconsented postinstall mutation of a foreign, broad AI-agent control surface. The lifecycle script silently installs unrestricted command hooks, which meets the install-hook a...
The package has a concrete automatic postinstall path that mutates foreign global AI-agent control surfaces. This meets the install-hook abuse blocking boundary despite the absence of dir...
This is an unconsented postinstall mutation of broad, pre-existing AI-agent control surfaces. The conditional checks and opt-outs do not establish user consent.
The package performs an automatic postinstall chain that alters consumer configuration and installs package-controlled AI-agent instructions and skills. Its generated instruction explicit...