Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 22:52 UTC. Ordered by latest scan.
Source confirms unconsented install-time mutation of the broad Codex skill control surface. This meets the firewall block boundary regardless of the otherwise conventional CLI authenticat...
This is a concrete unconsented postinstall mutation of broad, foreign AI-agent control surfaces. It meets the firewall block boundary even though the postinstall itself has no observed ne...
The install hook performs forced, silent writes to foreign AI-assistant configuration locations without an explicit user command. This meets the firewall block policy for unconsented post...
The postinstall behavior is concrete, silent, and modifies consumer-owned AI-agent configuration by default. That meets the install-control-surface block boundary despite the absence of e...