Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 21:10 UTC. Ordered by latest scan.
The automatic postinstall modifies foreign, user-wide AI-agent configuration and installs an MCP command that resolves the latest release at launch. This meets the install-control-surface...
The package has a concrete automatic postinstall chain that overwrites a foreign AI-agent executable with opaque payloads. That meets the install-control-surface blocking policy despite b...
The automatic lifecycle hook modifies a consumer-owned MCP configuration rather than only package-owned files. That creates an unconsented agent-extension execution path.
The package has a concrete automatic postinstall chain that overwrites skill content in Claude, agent, and Codex directories. Opt-out support does not establish consent for the default mu...