Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 14:41 UTC. Ordered by latest scan.
The install-time hook performs unconsented mutation of a foreign global agent/terminal extension surface and installs code configured for detached startup. This meets the blocking policy...
The source establishes a concrete install-time foreign AI-agent control-surface write and startup persistence chain. Lack of outbound traffic in the inspected plugin does not negate the p...
The inspected postinstall behavior concretely mutates foreign host AI-agent configuration and installs plugins automatically. This exceeds a first-party, user-invoked setup flow.
This is a concrete npm-postinstall mutation of a foreign, user-global AI-agent control surface. Conditional harness selection and tagged merging reduce scope but do not make the lifecycle...