Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 01:06 UTC. Ordered by latest scan.
The package performs unconsented postinstall mutation of broad, foreign AI-agent control surfaces and a user Python environment. That is concrete install-hook abuse under the stated policy.
This is an automatic postinstall write to a foreign, behavior-bearing AI-agent control surface, with recursive overwrite semantics. That concrete install-time mutation meets the blocking...
The package performs unconsented postinstall mutation of both Codex and Claude user skill directories, plus user-level dependency installation. This is concrete install-hook abuse under t...
The automatic postinstall hook modifies global Cursor agent configuration and skills, rather than requiring an explicit user setup action. This meets the install-hook abuse boundary for a...