Frontline CLI — Public API (agents, workflows, billing, tables, objects) + Max chat/admin REST from your terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. The npm postinstall hook can install bundled Claude Code skills into the user’s Claude skills directory. This is first-party agent extension setup and presents lifecycle risk, but the inspected behavior does not establish a concrete malicious attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/workflows/nodes.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkgThis report applies to @getfrontline/cli@1.8.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/workflows/nodes.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/max/browserLogin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/runPostinstall.mjsView on unpkg