Sort your Meta creatives into Scale, Wait and Kill on a spend vs CRR grid — drop-in Claude Code skill
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically adds a skill and executable scripts to the user's global Claude Code skills directory. This mutates a broad AI-agent control surface without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs its installer through a postinstall lifecycle hook.
package.jsonView on unpkg · L29Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-to-claude.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/config.cjs#virtual:normalized:round1View on unpkgThis report applies to @ads-repo/meta-creative-buckets@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L30The package automatically runs its installer through a postinstall lifecycle hook.
package.jsonView on unpkg · L29A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/config.cjs#virtual:normalized:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-to-claude.jsView on unpkg · L6