Update to the latest: npx @golproductions/check@latest --install
Less hallucinations. A command firewall for Claude Code: validates every shell command before execution, so fabricated commands are denied before they run.
LPM treats this as warn-only first-party agent extension lifecycle risk. An explicit installation command installs a persistent Claude Code hook and downloads its hook implementation. The hook transmits command-related data to the vendor service and can invoke local probes requested by that service.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L2This report applies to @golproductions/check@4.1.5.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L2