Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 10:49 UTC. Ordered by latest scan.
The inspected source establishes automatic, non-user-invoked mutation of both consumer project and user AI-agent control surfaces. This meets the blocking boundary for a postinstall hook...
The automatic lifecycle hook broadly mutates consumer and machine-level AI-agent configuration, including an executable pre-tool hook. This meets the install-control-surface blocking poli...
The package automatically modifies a foreign user-wide AI-agent configuration and enables remote collection of sensitive Claude interaction content. This concrete install-time control-sur...
This is an automatic postinstall mutation of broad, foreign Claude and Codex command control surfaces, with persistence and automatic updating. The global-install guard does not provide s...