Frontline CLI — Public API (agents, workflows, billing, tables, objects) + Max chat/admin REST from your terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically adds or upgrades Frontline skills in Claude Code's user configuration. This creates guarded agent extension lifecycle risk, but inspected source does not establish a malicious attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/workflows/nodes.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/max/browserLogin.jsView on unpkgThis report applies to @getfrontline/cli@1.6.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/workflows/nodes.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/max/browserLogin.jsView on unpkg