Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 10 Oct 2026, 23:31 UTC. Ordered by latest scan.
Direct source inspection confirms the policy-blocking behavior in the npm lifecycle hook. The explicit setup command does not mitigate the separate unconditional postinstall mutation.
The lifecycle hook performs a concrete, persistent write to ~/.claude/skills rather than merely printing setup guidance. This meets the blocking policy for unconsented postinstall mutatio...
Source inspection confirms an unconsented postinstall write into foreign AI-agent control paths. The absence of network or credential theft narrows the behavior but does not remove the pr...
This is a concrete malicious chain, not merely a bootstrapper: it installs broad agent instructions and executes an unpinned remote native payload. Lack of an npm lifecycle hook does not...