Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 20:24 UTC. Ordered by latest scan.
The package has an automatic postinstall path that writes package-controlled content into multiple foreign global AI-agent configuration surfaces. This meets the install-hook abuse policy...
Source implements a privileged vendor-service takeover, forged authentication state, and bypass of local tool approval, with optional authenticated traffic capture. The absence of install...
The package contains a concrete editor-control hijack and paid-tier bypass, not merely a user-configured proxy. Although it has no install hook, the explicit runtime path performs privile...
The postinstall hook performs unconsented, broad mutation of foreign AI-agent control surfaces. No exfiltration was found, but the automatic cross-platform persistence meets the install-h...