Update to the latest: npx @golproductions/check@latest --install
Less hallucinations. A command firewall for Claude Code: validates every shell command before execution, so fabricated commands are denied before they run.
LPM treats this as warn-only first-party agent extension lifecycle risk. An explicit install can fetch vendor-controlled hook code and register it as Claude Code hooks. Runtime command validation sends command metadata to the vendor service, and the MCP interface can execute shell commands.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2This report applies to @golproductions/check@4.1.9.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L2Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2