Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 15:50 UTC. Ordered by latest scan.
The automatic postinstall overwrite of multiple third-party AI-agent skill locations is concrete install-hook abuse. The lack of installer network activity does not remove the control-sur...
The automatic lifecycle hook writes package-controlled instructions into multiple foreign AI-agent skill directories. This meets the install-time AI-agent control-surface mutation block p...
This is unconsented postinstall mutation of foreign AI-agent configuration and instruction surfaces. It meets the install-hook abuse blocking policy even without demonstrated credential t...
The automatic postinstall rewrite of a separate AI-agent extension is a concrete foreign control-surface mutation. Its narrow visible purpose reduces certainty about broader intent but do...