Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 07:50 UTC. Ordered by latest scan.
The automatic postinstall modifies global Claude Code hooks and instructions without interactive consent. That meets the policy boundary for malicious install-hook abuse despite the packa...
The guarded global-install condition does not provide explicit consent for an npm lifecycle hook to install remote software and alter Codex plugin configuration. This is concrete install-...
The source contains a concrete AI-agent control message that attempts to override independent judgment. Although there is no npm install hook and verification is opt-in, this package-supp...
This package has a concrete automatic postinstall path that mutates a global OpenCode control surface, and an import-time self-healing path that repeats it. That meets the install-control...