Open a Claude Code multi-pane terminal workspace with one command (macOS and Windows)
LPM treats this as warn-only first-party agent extension lifecycle risk. The install hook runs a first-party asset sync that writes prompts, hooks, and templates into the user's Claude-related directories. This is an agent-extension lifecycle risk; inspected source did not establish malicious payload behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Package source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/win32-arm64/claudespace.dist/claudespace-bin.exeView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/agent-af47f7599efb1414f/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/darwin-arm64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/win32-arm64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/win32-x64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgThis report applies to @ayorcodes/claudespace@1.0.15.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Package source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/win32-arm64/claudespace.dist/claudespace-bin.exeView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/agent-af47f7599efb1414f/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/darwin-arm64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/win32-arm64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/win32-x64/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkg