Frontline CLI — Public API (agents, workflows, billing, tables, objects) + Max chat/admin REST from your terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package can automatically add bundled skills to the user's Claude Code skills directory. This is a guarded first-party agent-extension setup, not confirmed data theft or remote code execution.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs a postinstall hook automatically.
package.jsonView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgThis report applies to @getfrontline/cli@1.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21The package runs a postinstall hook automatically.
package.jsonView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkg