Static analysis completed at 0.0% confidence. No malicious behavior was detected; 30 low-signal pattern(s) were surfaced and cleared.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/litclaude-ai.jsView on unpkg · L1609Package source references weak cryptographic algorithms.
plugins/litclaude/skills/lit-typographic-motion/engine/node/ws-server.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
plugins/litclaude/lib/office_runtime_bootstrap.pyView on unpkgPackage ships high-entropy non-source blobs.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage ships compressed or archive-like blobs.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
plugins/litclaude/lib/motion-render-gate.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/automatic-update.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-notifier.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-real-surface-behaviors.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkgThis report applies to @litfamily/litclaude@1.0.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/litclaude-ai.jsView on unpkg · L1609Package source references weak cryptographic algorithms.
plugins/litclaude/skills/lit-typographic-motion/engine/node/ws-server.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
plugins/litclaude/lib/office_runtime_bootstrap.pyView on unpkgPackage ships high-entropy non-source blobs.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage ships compressed or archive-like blobs.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
plugins/litclaude/skills/lit-docx/templates/docx/korean-generic.docxView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
plugins/litclaude/lib/motion-render-gate.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/automatic-update.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-notifier.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-real-surface-behaviors.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkg