Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 12:54 UTC. Ordered by latest scan.
This package automatically overwrites skills across three agent ecosystems during installation. That is concrete install-hook abuse even though the installer itself has no network or cred...
This is an unconsented postinstall execution chain that installs AI-agent hooks through an opaque native binary. The visible source provides no bounded list of affected settings or integr...
This is concrete unconsented postinstall mutation of a foreign AI-agent control surface. The lack of direct secret theft does not neutralize the install-hook abuse.
The package performs unconsented postinstall mutation of existing workspace and agent MCP control surfaces. That is a concrete install-hook abuse path even though the reviewed code did no...