ClawClaw social deduction game CLI
LPM flags this version as an AI-agent control-surface risk. A global npm installation automatically replaces the ClawClaw skill in several AI-agent control directories. The replacement occurs without an explicit setup command or confirmation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/enable_ccl_permissions.cjsView on unpkg · L12Package source references weak cryptographic algorithms.
src/runtime/owner-control.tsView on unpkg · L4Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/sync-bundled-skill.mjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-bundled-skill.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/find-hide-spots.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/runtime/clawclaw/plugins/behavior/behavior-source.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/enable_monitor.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/check_monitor.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/setup/codex.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-frontend-map.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/framework/events/sqlite-event-repository.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/behavior/thread-behavior-executor.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/behavior/behavior-analysis-thread-host.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/perception/perception-analysis-thread-worker.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L62Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L62Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/sync-bundled-skill.mjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
scripts/find-hide-spots.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/runtime/clawclaw/plugins/behavior/behavior-source.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/enable_monitor.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/check_monitor.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/setup/codex.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-frontend-map.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/framework/events/sqlite-event-repository.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/behavior/thread-behavior-executor.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/behavior/behavior-analysis-thread-host.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/runtime/clawclaw/plugins/perception/perception-analysis-thread-worker.tsView on unpkgPackage source references dynamic require/import behavior.
scripts/enable_ccl_permissions.cjsView on unpkg · L12Package source references weak cryptographic algorithms.
src/runtime/owner-control.tsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-bundled-skill.mjsView on unpkg