Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 03:14 UTC. Ordered by latest scan.
The postinstall hook performs unconsented mutation of foreign/broad AI-agent skill surfaces. That concrete lifecycle behavior meets the blocking policy even though no credential exfiltrat...
The global-install guard limits scope but does not obtain user consent or prevent modification of the default Codex agent and shared host configuration. This meets the install-time foreig...
This is a concrete, unconsented postinstall mutation of foreign/broad AI-agent control surfaces. Localhost-only networking does not mitigate the install-time agent configuration changes.
This is an unconsented postinstall mutation of broad third-party AI-agent control surfaces, coupled with an unverified remote native-payload chain and persistence. The guards and careful...