Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
The source establishes unconsented postinstall mutation of a broad AI-agent control surface, which meets the explicit blocking rule. Same-vendor binaries and the PATH prerequisite do not...
The active postinstall chain performs unconsented broad deletion within a foreign AI agent control surface. This meets the blocking policy regardless of the legacy-cleanup explanation.
Inspected source establishes unconsented postinstall mutation of a global AI-agent instruction file. This meets the supplied blocking policy independently of citation coverage or any unpr...
Source proves unconsented postinstall mutation of Claude's global agent control surface, which meets the specified blocking policy. The separate interactive init command does not authoriz...