Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 9 Oct 2026, 21:57 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall chain that writes broad consumer AI-agent configuration and adds a blocking Claude hook. This meets the install-control-surface block poli...
The automatic lifecycle hook forcibly installs package-authored skills into both project and global Codex/Claude control directories. This meets the install-hook abuse blocking policy des...
This is an unconsented install-time mutation of a foreign AI-agent control surface, with persistent automatic execution of another registry package. The absence of observed secret theft d...
This package performs an automatic postinstall mutation of global AI-agent configuration, including a managed instruction block in an existing Codex control file. That is concrete install...