Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 17:14 UTC. Ordered by latest scan.
This is a concrete AI-agent control-hijack surface, not ordinary documentation: reviewer and release instructions are embedded in runtime prompt construction. The absence of install hooks...
This is concrete, unconsented postinstall mutation of broad foreign AI-agent control surfaces. The absence of observed exfiltration does not neutralize the automatic cross-platform contro...
This is concrete, automatic postinstall mutation of foreign AI-agent control surfaces plus execution of a remotely selected native binary and broad host changes. The global-install guard...
The automatic lifecycle hook broadly mutates a foreign consumer project's AI-agent control surface. This meets the publish-block policy regardless of the absence of observed exfiltration.