AI workflow templates for NextSpark - Claude Code agents, commands, skills, and multi-editor support
LPM flags this version as an AI-agent control-surface risk. Installation automatically replaces matching Claude agent instructions and capabilities in the consumer project or parent workspace. An existing Claude directory is treated as permission to modify it, without verifying package ownership.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs the postinstall script during installation.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L169Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L169Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgThis report applies to @nextsparkjs/ai-workflow@0.1.0-beta.194.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33package.json automatically runs the postinstall script during installation.
package.jsonView on unpkg · L33Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgPackage contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L169Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L169Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg