Review AI-agent capability abuse and control hijacking, including changes to agent configuration, instructions, or permissions. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The postinstall hook silently mutates user-level AI-agent configuration and installs a package-controlled MCP server with auto-approved tools. This is unconsented install-time control-sur...
Source confirms an automatic postinstall hook that rewrites MCP registrations for multiple agent clients and creates launchers. This meets the policy for unconsented mutation of foreign o...
The postinstall hook triggers setup across supported platforms, and the setup code writes AI-agent instructions and configures integrations. This meets the policy for unconsented install-...
The package performs unconsented install-time writes to global AI-client MCP configuration and registers a command that resolves brokre@latest. This is a concrete AI-agent control-surface...