Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 21:40 UTC. Ordered by latest scan.
The lifecycle hook performs automatic cross-agent configuration mutation, meeting the block boundary for a foreign/broad AI-agent control surface. No exfiltration was confirmed, but it is...
The automatic lifecycle script performs destructive credential/config mutation and credential replacement in a shared AI CLI directory. Package-aligned networking does not mitigate the un...
Source confirms the critical behavior rather than merely scanner hints: an automatic npm postinstall modifies global Claude configuration and injects a mutable MCP launch command. This me...
This is a concrete unconsented postinstall mutation of broad AI-agent control files in the consumer project. The templates appear design-system-oriented and no exfiltration was found, but...