Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 10:59 UTC. Ordered by latest scan.
The package performs unconsented postinstall mutation of broad, user-level Claude AI-agent control surfaces. Its MCP registration also uses a floating latest package reference.
This is unconsented postinstall mutation of a user-wide AI-agent control surface. The later workspace upload capability makes that automatic enablement security-significant.
This is an unconsented postinstall mutation of broad, foreign AI-agent control surfaces. The behavior is concrete in the lifecycle hook and runtime source, so it meets the block boundary.
The source confirms unconsented postinstall mutation of several foreign AI-agent configuration directories, including enabling a Codex plugin and MCP server. This meets the firewall block...