Claude Code Skills for Optima development team - cross-environment collaboration tools
LPM flags this version as an AI-agent control-surface risk. An npm postinstall hook changes global Claude and Codex agent control surfaces without a separate user command. No network exfiltration was identified in the installer.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L22Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L27Package source references child process execution.
bin/helpers/cn-deploy.tsView on unpkg · L34Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/verify-health.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/generate-test-token.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/verify-health.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L45Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L50Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L55This report applies to @optima-chat/dev-skills@0.16.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/verify-health.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/generate-test-token.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/verify-health.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L45Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L50Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L55Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L22Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L27Package source references child process execution.
bin/helpers/cn-deploy.tsView on unpkg · L34Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkg