Client feedback collection tool for Impakers OS
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package runs a postinstall script that plants a first-party Claude skill in the consumer project. The skill tells the agent how to map UI files for this feedback widget and can also insert an ESLint preset. No credential theft, remote payload, or destructive action was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/setup.mjsView on unpkg · L7Manifest entrypoint contains risky behavior absent from dist/build output.
scripts/setup.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/setup.mjsView on unpkgThis report applies to @impakers/debug@1.9.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L119Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
Manifest entrypoint contains risky behavior absent from dist/build output.
scripts/setup.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/setup.mjsView on unpkg