Agent Skill operator manual and policy files for Cassie
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package automatically adds a Cassie agent skill to global Claude and agent skill locations. The payload directs agents to operate a trading CLI, but this package itself does not execute that CLI or contact a network.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs its installer automatically through an npm postinstall hook.
package.jsonView on unpkg · L36Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L3Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
install.mjsView on unpkgThis report applies to @quotient-forecasting/cassie-skill@0.4.13.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
install.mjsView on unpkgThe installer creates and overwrites Cassie skill files in the global Claude and agent skill directories.
install.mjsView on unpkg · L12Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L37Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L37The package runs its installer automatically through an npm postinstall hook.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe installer creates and overwrites Cassie skill files in the global Claude and agent skill directories.
install.mjsView on unpkg · L12Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L3Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
install.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.mjsView on unpkg