Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 22:17 UTC. Ordered by latest scan.
The package has a concrete unconsented postinstall chain that changes foreign and broad AI-agent configuration surfaces. Its CI/local-install guard does not mitigate the global-install be...
This is concrete, unconsented postinstall mutation of foreign and broad AI-agent control surfaces, including trust state and always-on hooks. The guarded remote harvest path does not miti...
The lifecycle hook creates persistent, cross-client agent-control changes during installation, meeting the blocking policy. No network exfiltration is needed for this concrete control-sur...
This is concrete, unconsented postinstall mutation of a broad foreign AI-agent configuration surface. It meets the firewall block criterion regardless of otherwise normal CLI and bundled-...