Frontline CLI — Public API (agents, workflows, billing, tables, objects) + Max chat/admin REST from your terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. On installation, the package conditionally installs its bundled Frontline skills into an existing Claude Code skills directory. No confirmed exfiltration, remote payload, or destructive action was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgPostinstall detects Claude Code and copies bundled SKILL.md files into ~/.claude/skills.
dist/scripts/postinstall.jsView on unpkg · L103This report applies to @getfrontline/cli@1.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgPostinstall detects Claude Code and copies bundled SKILL.md files into ~/.claude/skills.
dist/scripts/postinstall.jsView on unpkg · L103