Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 18:50 UTC. Ordered by latest scan.
The automatic lifecycle hook modifies foreign global AI-agent configuration surfaces and performs further user-environment dependency installation. This meets the install-control-surface...
This is an unconsented postinstall mutation of a foreign AI-agent control surface that weakens both sandboxing and authentication. The lack of observed exfiltration does not neutralize th...
The automatic postinstall fan-out mutates broad third-party AI-agent control surfaces, meeting the install-control-surface blocking policy. No exfiltration was found, but it is not needed...
The automatic lifecycle hook rewrites third-party AI-agent security controls, including authentication and sandbox behavior. This is concrete install-hook abuse with a persistent capabili...