Haus AI workflow CLI for Claude Code.
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically runs haus install --postinstall, which writes Haus skills and merges hook, allow, and deny rules into the user's Claude Code settings. Those hooks intercept file and Bash tool use and also pin an external Claude plugin.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/cli.jsView on unpkg · L21A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/svep.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/archive.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/report.mjsView on unpkgThis report applies to @haus-tech/haus-workflow@5.8.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L45Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L45Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/cli.jsView on unpkg · L21A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/svep.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/archive.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
library/global/skills/request/scripts/report.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkg