Claude Code Skills for Optima development team - cross-environment collaboration tools
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies the user's Claude and Codex agent configuration directories. It adds all bundled commands and skills, expanding the agent control surface without an explicit setup action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L21Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L26Package source references child process execution.
bin/helpers/infisical-secrets.tsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/billing-http.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/cn-deploy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/generate-test-token.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/show-env.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/billing-http.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/cn-deploy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/show-env.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L44Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L49Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L54This report applies to @optima-chat/dev-skills@0.16.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/helpers/query-db.tsView on unpkg · L2Package source references child process execution.
bin/helpers/infisical-secrets.tsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkg · L119A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/helpers/logs.ts#virtual:normalized:round1View on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bin/helpers/logs.js#virtual:normalized:round1View on unpkg · L117Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/skills/yzsgo-e2e/bootstrap.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/billing-http.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/cn-deploy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/discount/generate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/generate-test-token.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/helpers/show-env.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/billing-http.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/cn-deploy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/helpers/show-env.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/helpers/db-utils.jsView on unpkgHardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L44Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L49Hardcoded password in dist/bin/helpers/query-db.js
dist/bin/helpers/query-db.jsView on unpkg · L54Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L21Hardcoded password in bin/helpers/query-db.ts
bin/helpers/query-db.tsView on unpkg · L26Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkg