CLI from Prevent Senior Tech
LPM flags this version as an AI-agent control-surface risk. The npm postinstall silently configures Claude Code for users who already have Claude installed. It adds MCP servers and changes agent permissions, plugins, and status-line behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgpackage.json defines a postinstall hook and a runtime dependency on the package itself.
package.jsonView on unpkg · L15A manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion.jsView on unpkg · L11Source writes installer persistence such as shell profile or service configuration.
src/commands/completion.jsView on unpkg · L11The postinstall script automatically calls the Claude configuration routine without a consent step.
scripts/postinstall.jsView on unpkg · L8This report applies to @preventsenior/pvs-cli@3.7.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15package.json defines a postinstall hook and a runtime dependency on the package itself.
package.jsonView on unpkg · L15A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion.jsView on unpkg · L11Source writes installer persistence such as shell profile or service configuration.
src/commands/completion.jsView on unpkg · L11The postinstall script automatically calls the Claude configuration routine without a consent step.
scripts/postinstall.jsView on unpkg · L8