Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 09:59 UTC. Ordered by latest scan.
This is a concrete automatic postinstall chain that broadly changes a consumer project's AI-agent configuration and enables an extra plugin. It meets the install-control-surface blocking...
The automatic postinstall hook writes a wildcard command into the consumer's Claude Code configuration. This meets the policy for malicious install-hook abuse even without proven secret t...
The package automatically and broadly alters a consumer project’s OpenCode agents, commands, skills, plugin files, and configuration. That meets the install-control-surface blocking polic...
The automatic postinstall hook mutates foreign AI-agent control surfaces in the consuming project and can overwrite an existing command. This is concrete unconsented install-time control-...