Open a Claude Code multi-pane terminal workspace with one command (macOS only)
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package runs postinstall, which executes a bundled compiled binary and copies this product's Claude Code commands and related assets into the user's Claude and AI config directories. That is first-party agent extension setup, but it is automatic and the binary cannot be reviewed, so hook or settings writes beyond the package's own command files remain unresolved.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Source fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/claudespace.dist/unicodedata.soView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage ships high-entropy non-source blobs.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage ships compressed or archive-like blobs.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/wonderful-cohen-d0657a/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgThis report applies to @ayorcodes/claudespace@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L19Source fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L10Package ships native binary artifacts.
libexec/claudespace.dist/unicodedata.soView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/claudespace-observe.shView on unpkgPackage ships high-entropy non-source blobs.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage ships compressed or archive-like blobs.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
ayorcodes-claudespace-1.0.3.tgzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/worktrees/wonderful-cohen-d0657a/bin/claudespace-observe.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claudespace-ask.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
libexec/claudespace.dist/claudespace/assets/tmux-plugins/resurrect/scripts/save.shView on unpkg