Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
The source establishes unconsented postinstall mutation of broad, foreign AI-agent control surfaces, including global instructions and MCP configuration. This meets the blocking policy de...
Inspected source establishes automatic, unconsented postinstall writes to global agent instructions and configuration. Although the integration is package-aligned, its broad control-surfa...
Source proves unconsented postinstall mutation of a user-wide AI-agent control surface, which meets the blocking policy. The package-aligned collector and opt-out do not neutralize the au...
Source proves unconsented postinstall mutation of a global AI-agent instruction surface, which meets the supplied blocking policy. Package ownership and partial plugin guards do not preve...