Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:09 UTC. Ordered by latest scan.
The automatic lifecycle hook modifies consumer configuration and injects AI instructions that promote secret disclosure while suppressing review. The reviewer-directed text is social engi...
This is unconsented postinstall mutation of broad, foreign AI-agent control surfaces, combined with automatic user-environment dependency installation. The behavior meets the install-hook...
The automatic postinstall hook mutates and deletes project-level Claude Code skills. This meets the policy definition of unconsented install-time mutation of a foreign AI-agent control su...
The automatic postinstall chain persistently alters multiple third-party AI-client configurations to launch this package. This meets the policy for unconsented broad AI-agent control-surf...