Hardware-bound credential vault for the LIFEAI infrastructure stack
LPM flags this version as an AI-agent control-surface risk. On Windows npm postinstall writes persistence and requests elevation. It also mutates Windows Terminal settings to add Claude/Codex launch profiles without an explicit CLI command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/watchdog.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
cli/commands/watchdog.jsView on unpkg · L7A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/index.jsView on unpkg · L944Package source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L836Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
cli/commands/install.jsView on unpkg · L21GitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L17Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L17Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
cli/commands/install.jsView on unpkg · L21GitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L17Package contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
cli/commands/watchdog.jsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/watchdog.jsView on unpkg · L7A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/index.jsView on unpkg · L944Package source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L836