AI workflow templates for NextSpark - Claude Code agents, commands, skills, and multi-editor support
LPM treats this as warn-only first-party agent extension lifecycle risk. After npm install, a postinstall hook can copy this package's Claude Code agents, commands, and skills into an existing project .claude folder. The copy is limited to NextSpark apps that already set up that folder and does not send data off-box.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall defines a postinstall hook that always launches scripts/postinstall.mjs.
package.jsonView on unpkg · L30Package contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgThis report applies to @nextsparkjs/ai-workflow@0.1.0-beta.190.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33Install defines a postinstall hook that always launches scripts/postinstall.mjs.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgPackage contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg