Claude Code-native workflow distribution.
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm installation can trigger setup of the package's own Claude Code plugin and HUD.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/qa-uiux-visual-qa-scenarios.mjsView on unpkg · L83Package ships non-JavaScript build or shell helper files.
plugins/litclaude/skills/deep-interview/scripts/render_progress.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/litclaude-ai.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/automatic-update.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-notifier.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/litclaude-ai.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-real-surface-behaviors.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkgThis report applies to @litfamily/litclaude@1.0.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L41Package ships non-JavaScript build or shell helper files.
plugins/litclaude/skills/deep-interview/scripts/render_progress.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
plugins/litclaude/vendor/scientific-visualization/tests/test_figure_export.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/litclaude-ai.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/automatic-update.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-notifier.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/litclaude-ai.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lsp-setup/scripts/verify-lsp.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-negative-gate-matrix.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-real-surface-behaviors.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/skills/lit-code/scripts/typescript/check-no-excuse-rules.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inspect-agent-tools.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/qa-installed-tamper-repair.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tools/check-model-routing.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/barrier-detection.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/litclaude/lib/public-source-reader/guard.mjsView on unpkgPackage source references dynamic require/import behavior.
scripts/qa-uiux-visual-qa-scenarios.mjsView on unpkg · L83