Standalone refactor CLI driving any LSP server: project-wide rename, file-move with importer updates, and code actions.
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall creates a first-party Claude skill under the user's AI-agent skills directory. No exfiltration, remote endpoint, or arbitrary payload execution was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
skillit-postinstall.cjsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/connect.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/connect.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L70Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/connect.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/connect.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
skillit-postinstall.cjsView on unpkg · L26