Fresh-context iterative loops for Claude Code — autonomous task completion with independent verification
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall installs a first-party Claude Code slash command and RLP Desk runtime under ~/.claude. Explicit RLP Desk workflows can launch Claude/Codex with approval safeguards disabled and grant its project runtime directory permissions; no exfiltration or remote payload path was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source references dynamic require/import behavior.
scripts/postinstall.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/node/reporting/campaign-reporting.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/node/run.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/node/reporting/campaign-reporting.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/node/run.mjsView on unpkgPackage source references dynamic require/import behavior.
scripts/postinstall.jsView on unpkg · L3Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkg