奇绩创坛命令行工具(mplus CLI)
LPM flags this version as an AI-agent control-surface risk. On installation, the package writes its bundled skills and commands into broad user-level AI-agent control directories. These files can affect future agent behavior without a user invoking the CLI setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/mplus.jsView on unpkg · L3Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/registry.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall-skills.jsView on unpkg · L5This report applies to @miracleplus/mplus@0.6.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/mplus.jsView on unpkg · L3Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/registry.jsView on unpkg · L1