Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 16:34 UTC. Ordered by latest scan.
Automatic installation mutates a foreign, user-wide AI-agent control surface and installs unrestricted command hooks. This is concrete install-hook abuse regardless of the Telora binary n...
This is an unconsented post-install takeover of a foreign AI command's per-user executable and configuration surface, reinforced by package-name and README inconsistency. The absence of d...
This is an unconsented postinstall mutation of broad, foreign AI-agent control surfaces, with an additional user-environment package installation. The behavior meets the install-control-s...
The automatic lifecycle chain mutates Claude Code and VS Code AI configuration and enables telemetry hooks without a user setup command. This meets the install-control-surface blocking rule.