Claude Code Skills for Optima development team - cross-environment collaboration tools
LPM flags this version as an AI-agent control-surface risk. npm postinstall silently mutates global Claude and Codex agent instruction surfaces. It installs commands and skills that can influence future agent behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L21Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L26Package source references child process execution.
bin/helpers/infisical-secrets.tsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L44Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L49Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L54Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Package source references child process execution.
bin/helpers/infisical-secrets.tsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L44Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L49Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L54Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L21Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L26Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6