Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 20:21 UTC. Ordered by latest scan.
The lifecycle hook performs broad, persistent AI-agent configuration mutation in a consuming project and changes package-manager lifecycle behavior. This meets the install-time foreign/br...
The package performs unconsented postinstall mutation of broad, foreign AI-agent control surfaces during global installation. Under the stated policy this is block-worthy even without sep...
Source confirms an unguarded npm postinstall mutates Claude Code configuration in the consumer project and runs pip installation. This meets the install-control-surface block policy despi...
The postinstall creates a foreign, global Claude Code control surface rather than limiting setup to an explicit CLI command or the target project. This meets the blocking policy despite n...