Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 00:20 UTC. Ordered by latest scan.
The automatic postinstall chain deliberately modifies the consumer project's AI-agent instruction and adapter surfaces across multiple vendors. This satisfies the policy for malicious ins...
Source inspection confirms automatic postinstall mutation of consumer project and Claude Code plugin state, including marketplace refresh and third-party plugin installation. This meets t...
The automatic postinstall hook modifies multiple external AI-agent instruction files and injects behavioral guidance. This meets the policy definition of malicious install-hook abuse.
This package performs an automatic postinstall mutation of several foreign AI-agent control surfaces and injects instructions for financial and credential-related actions. This meets the...