Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 21:04 UTC. Ordered by latest scan.
Although the stated feature is benign and documented, the package performs the policy-defined blocking behavior: postinstall mutation of a foreign AI-agent control surface. No exfiltratio...
Source inspection confirms an unconsented postinstall mutation of broad Claude project controls, plus a telemetry chain that accesses session metadata and transcript-derived usage. This m...
Direct source inspection confirms unconsented postinstall mutation of broad, foreign AI-agent configuration and permission surfaces. This meets the firewall block boundary regardless of t...
The postinstall hook concretely deletes foreign AI runtime packages during installation. Global-only scope and opt-outs reduce breadth but do not make the unconsented lifecycle mutation s...