Verified coding workflows for the terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. A postinstall hook can set up a Cline MCP integration and install Cline guidance files. This is a guarded agent-extension capability rather than a confirmed covert attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth/oauth.jsView on unpkgThis report applies to @flotic/minitok@1.4.13.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Package text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth/oauth.jsView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5