AI workflow templates for NextSpark - Claude Code agents, commands, skills, and multi-editor support
LPM treats this as warn-only first-party agent extension lifecycle risk. Automatic installation can update an existing NextSpark consumer's Claude Code extension files. No credential theft, payload download, or external exfiltration was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package registers an automatic postinstall hook that launches its setup script when a NextSpark project already has a .claude directory.
package.jsonView on unpkg · L30Package contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgThis report applies to @nextsparkjs/ai-workflow@0.1.0-beta.191.
See version security history for other recorded verdicts.
Evidence last updated: .
The package registers an automatic postinstall hook that launches its setup script when a NextSpark project already has a .claude directory.
package.jsonView on unpkg · L30Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.mjsView on unpkgPackage contains a high-severity secret pattern.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Stripe test secret key in claude/skills/nextjs-api-development/scripts/generate-crud-tests.py
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg · L174Package ships non-JavaScript build or shell helper files.
claude/skills/nextjs-api-development/scripts/generate-crud-tests.pyView on unpkg