Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 14:01 UTC. Ordered by latest scan.
The package’s automatic postinstall mutates foreign AI-agent control surfaces and host configuration. This meets the blocking policy for unconsented install-time broad AI-agent control-su...
The concrete, unconsented global postinstall overwrite of the codex AI-agent command is sufficient for blocking. No network exfiltration is needed for this control-surface hijack.
Direct source inspection confirms automatic writes into ~/.claude/skills and ~/.codex/skills, not merely a user-invoked setup command. This meets the install-time foreign AI-agent control...
The lifecycle hook performs broad AI-client configuration and executable MCP registration by default, rather than limiting setup to an explicit user command or a package-owned surface. No...