Neocortex v4.60.45 - Orquestrador de Desenvolvimento de Epics & Stories para Claude Code
LPM flags this version as an AI-agent control-surface risk. An npm postinstall hook automatically launches a quiet installer during global installation. The installer defaults to a Claude Code target and writes Neocortex agent files into the user's AI-agent configuration area.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L475Package source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
packages/client/dist/runner/scheduler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/continuous-story-workspace.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-merge-candidate-qa.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-terminal-git-cli-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/types.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/tier/tier-aware-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/nx-invoke-signature.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/strict-readonly.jsView on unpkgThis report applies to @ornexus/neocortex@4.60.45.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L102Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L102Package ships non-JavaScript build or shell helper files.
targets-stubs/cursor/install-cursor.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
packages/client/dist/runner/scheduler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/continuous-story-workspace.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/scheduler.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-merge-candidate-qa.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/epic-terminal-git-cli-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/runner/headless/types.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/tier/tier-aware-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/nx-invoke-signature.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/shared/dist/strict-readonly.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install.jsView on unpkgPackage source invokes a package manager install command at runtime.
install.jsView on unpkg · L475Package source references dynamic require/import behavior.
targets-stubs/lib/managed-config-merge.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
packages/client/dist/commands/invoke.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
packages/client/dist/commands/invoke.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
packages/client/dist/config/secure-config.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/client/dist/config/secure-config.jsView on unpkg