Hardware-bound credential vault for the LIFEAI infrastructure stack
LPM flags this version as an AI-agent control-surface risk. Installing the package on Windows automatically persists a hidden elevated watchdog and mutates Windows Terminal profiles that launch Claude and Codex. It also silently installs system dependencies.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/serve.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
cli/commands/serve.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/index.jsView on unpkg · L946Package source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L838Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
cli/commands/install.jsView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/codevelop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L17Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L17Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/serve.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
cli/commands/serve.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/codevelop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L17Package contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/index.jsView on unpkg · L946Package source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L838Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
cli/commands/install.jsView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/install.jsView on unpkg