Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 05:46 UTC. Ordered by latest scan.
This is a concrete unconsented postinstall mutation of foreign AI-agent control surfaces, meeting the blocking policy. No separate credential-exfiltration chain is needed for this verdict.
Direct source inspection confirms a postinstall chain that writes broad third-party agent control files and persistent Git hooks in the parent project. This meets the firewall block bound...
The install hook performs an unconsented, externally sourced mutation of a broad AI-agent control surface. This meets the install-control-surface block policy.
The lifecycle behavior is concrete source code, not a scanner inference. It meets the firewall block policy for unconsented postinstall mutation of a foreign/broad AI-agent control surface.