Lodestar (夜航星) — IM-native frontend for Codex, Claude Agent SDK and DeepSeek Harness via Feishu Card Kit
LPM treats this as warn-only first-party agent extension lifecycle risk. npm install runs a postinstall script that deletes the package-owned lodestar-files skill under Codex and Claude home skill directories and under the Lodestar managed Claude plugin directory. Deletion happens only after the skill file name matches, and an environment variable can skip it.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/lodestar.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lodestar.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/lodestar.jsView on unpkg · L44Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lodestar.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/lodestar.jsView on unpkg · L44Package source references dynamic require/import behavior.
dist/lodestar.jsView on unpkg · L18Source passes code obtained from a remote response into a dynamic execution sink.
node_modules/mathjax-full/es5/ui/menu.jsView on unpkg · L1Package source references dynamic code evaluation.
node_modules/mathjax-full/es5/ui/menu.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
src/managed-skill-cleanup.cjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/managed-skill-cleanup.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@xmldom/xmldom/lib/dom-parser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-version.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/makeAllView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/packView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-agent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/versionView on unpkgThis report applies to @leviyuan/lodestar@0.19.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L46Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L46Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/lodestar.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
src/managed-skill-cleanup.cjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/managed-skill-cleanup.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@xmldom/xmldom/lib/dom-parser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-version.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/makeAllView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/packView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-agent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lodestar-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/mathjax-full/components/bin/versionView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lodestar.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/lodestar.jsView on unpkg · L44Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lodestar.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/lodestar.jsView on unpkg · L44Package source references dynamic require/import behavior.
dist/lodestar.jsView on unpkg · L18Package source references dynamic code evaluation.
node_modules/mathjax-full/es5/ui/menu.jsView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
node_modules/mathjax-full/es5/ui/menu.jsView on unpkg · L1