Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 19:38 UTC. Ordered by latest scan.
The automatic lifecycle mutates shared third-party AI-agent configuration directories and user-level dependencies. This is a concrete unconsented install-hook attack surface.
The automatic lifecycle hook overwrites consumer Claude behavior and expands MCP permissions without an explicit user command. This meets the install-time AI-agent control-surface abuse b...
This is an automatic install-time delivery chain that plants an AI-directed prompt and induces broad, persistent modification of the consumer project's agent control surfaces. The behavio...
This is unconsented postinstall mutation of a broad foreign AI-agent control surface. CI and opt-out guards reduce exposure but do not make the default consumer-project modifications safe.