Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 03:52 UTC. Ordered by latest scan.
The confirmed install-time Claude Desktop configuration mutation meets the block policy for a foreign/broad AI-agent control surface. Other shell and network features are runtime video-ed...
Source inspection confirms a postinstall hook that mutates a broad set of foreign AI-agent configuration files. This meets the install-control-surface block criterion regardless of the op...
Direct source inspection confirms a concrete, automatic postinstall AI-agent control-surface takeover. The absence of exfiltration does not mitigate the unconsented cross-tool persistence.
The lifecycle source establishes an unconsented postinstall mutation of foreign, broad AI-agent control surfaces. This meets the blocking policy despite no observed network exfiltration.