Less hallucinations. A command firewall for Claude Code: validates every shell command before execution, so fabricated commands are denied before they run.
An explicit CLI installation registers hooks in the user's Claude Code configuration. The obfuscated executable fetches remote hook content and writes it under the user's home directory, enabling server-supplied code to run for agent events.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2The executable entrypoint is a heavily obfuscated Node program.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2This report applies to @golproductions/check@4.1.8.
See version security history for other recorded verdicts.
Evidence last updated: .
The executable entrypoint is a heavily obfuscated Node program.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2