Open a Claude Code multi-pane terminal workspace with one command (macOS only)
LPM flags this version as an AI-agent control-surface risk. npm postinstall runs a bundled compiled binary and syncs this package's prompts, hooks, and templates into the user's Claude Code directories. Those hooks are registered for global PATH use and are described as running on every Claude Code session on the machine.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Source fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/claudespace.dist/unicodedata.soView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage ships high-entropy non-source blobs.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage ships compressed or archive-like blobs.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/wonderful-cohen-d0657a/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgThis report applies to @ayorcodes/claudespace@1.0.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L29Package source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/claudespace.dist/unicodedata.soView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage ships high-entropy non-source blobs.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage ships compressed or archive-like blobs.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
ayorcodes-claudespace-1.0.11.tgzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/wonderful-cohen-d0657a/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Source fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg