Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 17:46 UTC. Ordered by latest scan.
Source confirms automatic postinstall writes to existing foreign AI-agent configuration and command-hook surfaces. This meets the block boundary regardless of the absence of observed cred...
Source confirms an install-time mutation of foreign AI-agent command names and a subsequent credential-routing, persistent full-access configuration chain. Collision checks reduce acciden...
The confirmed postinstall mutation of the host project's Cursor rules meets the blocking policy for an unconsented foreign AI-agent control-surface write. Other reviewed scripts do not mi...
The lifecycle script directly installs package-controlled instructions into the user's Claude skill directory. This meets the block threshold for unconsented postinstall mutation of a for...