Agent Skill operator manual and policy files for Cassie
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically adds or replaces a Cassie agent skill in two home-directory agent control surfaces. That skill gives agents instructions for operating trading bots, funding, withdrawals, and deployments.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe manifest runs install.mjs automatically after npm installation.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L3Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
install.mjsView on unpkgThis report applies to @quotient-forecasting/cassie-skill@0.4.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
install.mjsView on unpkgThe installer targets both the .agents and .claude skill directories in the user's home directory.
install.mjsView on unpkg · L12Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L37Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L37The manifest runs install.mjs automatically after npm installation.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe installer targets both the .agents and .claude skill directories in the user's home directory.
install.mjsView on unpkg · L12Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L3Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
install.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.mjsView on unpkg