Client feedback collection tool for Impakers OS
LPM flags this version as an AI-agent control-surface risk. An automatic install hook changes the consumer project's Claude agent control surface. No network attack was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/setup.mjsView on unpkg · L7Manifest entrypoint contains risky behavior absent from dist/build output.
scripts/setup.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/debug-widget-DVG4YNS5.jsView on unpkgThis report applies to @impakers/debug@1.9.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L119Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/debug-widget-DVG4YNS5.jsView on unpkgManifest entrypoint contains risky behavior absent from dist/build output.
scripts/setup.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkg