Hardware-bound credential vault for the LIFEAI infrastructure stack
An npm postinstall hook installs an elevated, persistent Windows watchdog. The watchdog repeatedly launches the package daemon in a hidden process, and the hook can silently install additional system software.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/watchdog-registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/fingerprint.jsView on unpkgPackage source executes code through a VM context API.
cli/supervisor-ui.test.jsView on unpkg · L143Source appears to send environment or credential material to an external endpoint.
cli/commands/serve.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli/commands/serve.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/http/components/system-component.jsView on unpkg · L147Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/install.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/bootstrap.cjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap.cjsView on unpkgPackage source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L829A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli/dashboard/dashboard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/watchdog.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/login.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/lib/fs-git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/ops/deployment-adapter.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L18A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/serve.jsView on unpkg · L6Source writes installer persistence such as shell profile or service configuration.
cli/commands/serve.jsView on unpkg · L6Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/http/components/system-component.jsView on unpkg · L147Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/install.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/bootstrap.cjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap.cjsView on unpkgPackage source invokes a package manager install command at runtime.
cli/index.jsView on unpkg · L829A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli/dashboard/dashboard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/watchdog.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/login.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/lib/fs-git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/ops/deployment-adapter.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L18Package contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/watchdog-registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/fingerprint.jsView on unpkgPackage source executes code through a VM context API.
cli/supervisor-ui.test.jsView on unpkg · L143Source writes installer persistence such as shell profile or service configuration.
cli/commands/serve.jsView on unpkg · L6Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
cli/commands/serve.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/serve.jsView on unpkg · L6