MORPH-SPEC: NLH (Natural Language Harness) for spec-driven development with Claude Code
LPM flags this version as an AI-agent control-surface risk. npm installation mutates the user-wide Claude Code configuration and installs a command executed by every Claude Code session. It also changes the Windows PowerShell profile.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
framework/hooks/claude-code/core/post-edit-typecheck.jsView on unpkg · L16Package source invokes a package manager install command at runtime.
framework/hooks/claude-code/core/post-edit-typecheck.jsView on unpkg · L7A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/lib/installers/mcp-installer.jsView on unpkg · L189Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lib/installers/mcp-installer.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/utils/hooks-installer.jsView on unpkg · L14Package ships non-JavaScript build or shell helper files.
framework/hooks/claude-code/statusline.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/dashboard/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
framework/templates/project/validate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lib/validators/ui/ui-contrast-validator.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/project/doctor.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L59Package ships non-JavaScript build or shell helper files.
framework/hooks/claude-code/statusline.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/commands/dashboard/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
framework/templates/project/validate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lib/validators/ui/ui-contrast-validator.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/project/doctor.jsView on unpkgPackage source references child process execution.
framework/hooks/claude-code/core/post-edit-typecheck.jsView on unpkg · L16Package source invokes a package manager install command at runtime.
framework/hooks/claude-code/core/post-edit-typecheck.jsView on unpkg · L7A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/lib/installers/mcp-installer.jsView on unpkg · L189Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lib/installers/mcp-installer.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/utils/hooks-installer.jsView on unpkg · L14