Claude Code Skills for Optima development team - cross-environment collaboration tools
LPM treats this as warn-only first-party agent extension lifecycle risk. Automatic installation mutates local AI-agent command and skill directories. No credential theft, remote payload, or destructive action was confirmed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/query-db.tsView on unpkgHardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L22Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L27Package source references child process execution.
bin/helpers/cn-deploy.tsView on unpkg · L34Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/cn-deploy.tsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/query-db.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L45Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L50Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/verify-health.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/cn-deploy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/safe-exec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/verify-health.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/safe-exec.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgThis report applies to @optima-chat/dev-skills@0.16.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Hardcoded password in dist/bin/helpers/query-db.js
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/query-db.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L45Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L50Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/verify-health.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/cn-deploy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/safe-exec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/verify-health.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/safe-exec.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/query-db.tsView on unpkgHardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L22Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L27Package source references child process execution.
bin/helpers/cn-deploy.tsView on unpkg · L34Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/cn-deploy.tsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js