Neocortex v4.60.30 - Orquestrador de Desenvolvimento de Epics & Stories para Claude Code
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically runs an installer that changes AI-agent configuration and installs user-scope MCP integrations. It also deletes selected files under multiple AI-tool homes.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L462Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgPackage source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/continuous-story-workspace.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/run-yoloop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-merge-candidate-qa.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-terminal-git-cli-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/types.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/tier/tier-aware-client.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/commands/invoke.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L93Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L93A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/continuous-story-workspace.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/run-yoloop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-merge-candidate-qa.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-terminal-git-cli-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/types.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/tier/tier-aware-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L462Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgPackage source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/commands/invoke.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkg