Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 15:18 UTC. Ordered by latest scan.
Source confirms the lifecycle hook and automatic cross-agent skill mutation; this meets the install-control-surface block boundary. Scanner similarity labels were not relied upon.
The source establishes a concrete postinstall chain that persists package-controlled instructions and lifecycle execution in global agent configuration. This meets the block policy for un...
Concrete install-time mutation of both Claude Code and Codex global MCP configuration meets the block policy for unconsented foreign/broad AI-agent control-surface writes.
The source confirms a concrete npm postinstall chain that writes and merges package-controlled content into broad external AI-agent control surfaces. This meets the blocking policy regard...