Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
Inspected source establishes unconsented postinstall mutation of foreign and shared AI-agent control surfaces, which meets the blocking policy. Blocking rests on the automatic instruction...
Source establishes unconsented postinstall mutation of foreign, global AI-agent control surfaces. This meets the blocking policy regardless of the delegation feature's package alignment.
Source establishes unconsented postinstall mutation of a shared Pi agent instruction file, including a user-directory fallback. This meets the blocking rule for foreign or broad AI-agent...
The source establishes an unconsented postinstall mutation of a shared AI-agent control surface, including a user-wide fallback. Under the supplied policy, this warrants blocking despite...