Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 07:59 UTC. Ordered by latest scan.
This package automatically changes foreign AI-agent instruction and configuration surfaces during global installation, and its injected instructions explicitly remove operator consent fro...
The package has a concrete automatic lifecycle path that writes third-party AI-agent configuration and skills. The global-install guard and loopback endpoint reduce scope but do not estab...
This is unconsented postinstall mutation of broad AI-agent control surfaces in the consumer project. No separate network or credential-theft behavior is required to establish the install-...
The automatic global-install hook changes foreign, broad Codex and Claude Code control surfaces, including a default agent definition. That meets the install-hook abuse policy despite the...