Claude Code-native workflow distribution.
LPM flags this version as an AI-agent control-surface risk. A global npm installation automatically configures Claude Code without an explicit installer command. It registers and enables the package plugin, writes marketplace records, and configures a command status line in global Claude settings.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/qa-uiux-visual-qa-scenarios.mjsView on unpkg · L83Package ships non-JavaScript build or shell helper files.
plugins/litclaude/skills/deep-interview/scripts/render_progress.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/litclaude-ai.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkgThis report applies to @litfamily/litclaude@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/qa-uiux-visual-qa-scenarios.mjsView on unpkg · L83Package ships non-JavaScript build or shell helper files.
plugins/litclaude/skills/deep-interview/scripts/render_progress.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/litclaude-ai.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkg