TypeScript client for SignalARRR — type-safe RPC over SignalR
No confirmed active attack surface exists in the inspected package snapshot. The install hook cannot copy its intended assets because they are absent.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L4The postinstall code is designed to copy package skills into existing project .claude and .github directories.
scripts/postinstall.cjsView on unpkg · L20The postinstall code is designed to copy package skills into existing project .claude and .github directories.
scripts/postinstall.cjsView on unpkg · L35This report applies to @cocoar/signalarrr@5.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21The postinstall code is designed to copy package skills into existing project .claude and .github directories.
scripts/postinstall.cjsView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L4The postinstall code is designed to copy package skills into existing project .claude and .github directories.
scripts/postinstall.cjsView on unpkg · L35