Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 00:48 UTC. Ordered by latest scan.
This is concrete unconsented postinstall mutation of foreign AI-agent configuration, meeting the blocking policy. Explicit-user ai-trash setup does not mitigate the independent postinstal...
The lifecycle behavior is concrete and package-controlled, not a scanner-only inference. It meets the firewall block rule for unconsented postinstall mutation of broad foreign AI-agent co...
The automatic postinstall mutation of foreign AI-agent skill directories is a concrete unconsented control-surface write. Source inspection found no remote payload fetch, but that does no...
Direct inspection confirms an npm postinstall mutates the foreign global Claude Code control surface and installs persistent hooks. The prior-setup guard limits reach but does not establi...