Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 02:00 UTC. Ordered by latest scan.
The lifecycle behavior is a concrete unconsented cross-vendor AI-agent control-surface mutation, meeting the blocking policy. No separate exfiltration chain is needed for this verdict.
The source confirms an unconsented postinstall mutation of foreign, broad AI-agent control surfaces. Safety checks and lack of network exfiltration do not remove that concrete persistence...
The package's postinstall concretely changes foreign global agent configuration, including Codex's generic default agent. Global-only guarding and non-overwrite behavior reduce collateral...
The package's proxy functionality is package-aligned, but its automatic global postinstall configures foreign Codex and Claude control surfaces, including the generic Codex default agent....