My Claude Code (MCC): route Claude Code and other coding agents to any model provider through one local proxy with a dashboard. This npm package installs and launches the Python server.
A global npm installation automatically retrieves and executes a remote installer script. The script is selected from a mutable repository branch and is not included or integrity-pinned in this package.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/my-claude-code.jsView on unpkg · L19Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/my-claude-code.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/my-claude-code.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/runtime-install.js#virtual:normalized:round1View on unpkg · L17A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/runtime-install.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/runtime-install.jsView on unpkgThis report applies to @firedmosquito831/my-claude-code@6.77.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/my-claude-code.jsView on unpkg · L19Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/my-claude-code.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/my-claude-code.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/runtime-install.js#virtual:normalized:round1View on unpkg · L17A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/runtime-install.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/runtime-install.jsView on unpkg