Claude Code governance framework that applies guardrails, guidance, and automated enforcement to projects
LPM flags this version as an AI-agent control-surface risk. Installing the package mutates a consumer project without an explicit command. It applies templates, changes Claude hook settings, injects a future postinstall command, and persists a Git merge-driver command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
harper-fabric/create-only/.github/workflows/deploy.ymlView on unpkg · L98Package source references dynamic require/import behavior.
harper-fabric/copy-overwrite/eslint.config.tsView on unpkg · L32Package source executes code through a VM context API.
scripts/check-ui-demo-data.mjsView on unpkg · L89Package ships non-JavaScript build or shell helper files.
harper-fabric/create-only/scripts/zap-baseline.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/lisa-expo/.codex-plugin/skills/container-view-pattern/scripts/validate_component.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
all/copy-overwrite/scripts/check-orphaned-branches.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/setup-project.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli/setup-project.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-automations-adapters.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-observability-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/update-cmd.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/kane-cli-process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/kane-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/standards/git-state.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/postinstall-trampoline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-deploy-pipeline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/learnings-merge-driver-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/standards/capture.jsView on unpkgHardcoded password in plugins/lisa-wiki-copilot/scripts/wiki-safety.mjs
plugins/lisa-wiki-copilot/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/lisa-wiki/scripts/wiki-safety.mjs
plugins/lisa-wiki/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/lisa-wiki-agy/scripts/wiki-safety.mjs
plugins/lisa-wiki-agy/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/lisa-wiki-cursor/scripts/wiki-safety.mjs
plugins/lisa-wiki-cursor/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/src/wiki/scripts/wiki-safety.mjs
plugins/src/wiki/scripts/wiki-safety.mjsView on unpkg · L14Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8Package ships non-JavaScript build or shell helper files.
harper-fabric/create-only/scripts/zap-baseline.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/lisa-expo/.codex-plugin/skills/container-view-pattern/scripts/validate_component.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
all/copy-overwrite/scripts/check-orphaned-branches.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/setup-project.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli/setup-project.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-automations-adapters.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-observability-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/update-cmd.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/kane-cli-process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/kane-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/standards/git-state.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/postinstall-trampoline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/ui-deploy-pipeline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/learnings-merge-driver-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/standards/capture.jsView on unpkgHardcoded password in plugins/lisa-wiki-cursor/scripts/wiki-safety.mjs
plugins/lisa-wiki-cursor/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/src/wiki/scripts/wiki-safety.mjs
plugins/src/wiki/scripts/wiki-safety.mjsView on unpkg · L14Package contains a possible secret pattern.
harper-fabric/create-only/.github/workflows/deploy.ymlView on unpkg · L98Package source references dynamic require/import behavior.
harper-fabric/copy-overwrite/eslint.config.tsView on unpkg · L32Package source executes code through a VM context API.
scripts/check-ui-demo-data.mjsView on unpkg · L89Hardcoded password in plugins/lisa-wiki-copilot/scripts/wiki-safety.mjs
plugins/lisa-wiki-copilot/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/lisa-wiki/scripts/wiki-safety.mjs
plugins/lisa-wiki/scripts/wiki-safety.mjsView on unpkg · L14Hardcoded password in plugins/lisa-wiki-agy/scripts/wiki-safety.mjs
plugins/lisa-wiki-agy/scripts/wiki-safety.mjsView on unpkg · L14