TypeScript client for SignalARRR — type-safe RPC over SignalR
LPM flags this version as an AI-agent control-surface risk. On npm installation, the package attempts to populate AI-agent-related directories in the consuming project. It targets existing .claude and .github directories and overwrites the signalarrr skill subtree.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs a postinstall hook automatically.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L4The hook writes package-provided skill content into existing .claude and .github directories in the consuming project.
scripts/postinstall.cjsView on unpkg · L26The hook writes package-provided skill content into existing .claude and .github directories in the consuming project.
scripts/postinstall.cjsView on unpkg · L41This report applies to @cocoar/signalarrr@5.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21The package runs a postinstall hook automatically.
package.jsonView on unpkg · L15Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L4The hook writes package-provided skill content into existing .claude and .github directories in the consuming project.
scripts/postinstall.cjsView on unpkg · L26The hook writes package-provided skill content into existing .claude and .github directories in the consuming project.
scripts/postinstall.cjsView on unpkg · L41