Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 07:07 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall path that modifies broad consumer AI-agent configuration and instruction files. This meets the install-hook abuse blocking policy even wit...
The postinstall path unconditionally configures global Claude telemetry that captures AI-session content and directs it externally. This meets the install-time AI-agent control-surface ab...
The package has a registry-install postinstall hook that automatically changes multiple foreign AI-agent control surfaces and shell profiles. This meets the install-hook abuse boundary re...
The automatic lifecycle hook installs a bundled capability into global locations for many unrelated AI-agent products. Guard checks reduce accidental overwrite risk but do not establish u...