Qianfan CLI - 千帆 MaaS 命令行工具
LPM treats this as warn-only first-party agent extension lifecycle risk. A postinstall hook downloads and executes an opaque platform binary. During global installation it automatically invokes that binary to connect to detected AI-agent skill locations.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L20Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
scripts/run.jsView on unpkg · L28This report applies to @mingliuyiming/qianfan-cli-test@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L23Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L23Package source references child process execution.
scripts/postinstall.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L20This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
scripts/run.jsView on unpkg · L28