Neocortex v4.60.28 - Orquestrador de Desenvolvimento de Epics & Stories para Claude Code
LPM flags this version as an AI-agent control-surface risk. A global npm installation automatically changes the user's Claude Code control surface. It deletes selected files and registers MCP tools and a remote service configuration without an interactive consent step.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L462Package source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/nx-invoke-signature.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/strict-readonly.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L92Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L92A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/nx-invoke-signature.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/strict-readonly.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L462Package source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkg