Install SiteDesk — automated back office for independent building contractors
LPM treats this as warn-only first-party agent extension lifecycle risk. Running the CLI performs privileged OS setup, installs dependencies from remote scripts, and configures SiteDesk's Claude environment. It enables bypassed Claude permissions and installs plugins in a package-owned configuration directory.
Package contains a possible secret pattern.
payload/platform/scripts/smoke-boot-services.shView on unpkg · L349A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/index.jsView on unpkg · L142Source downloads or fetches remote code and executes it.
dist/index.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L285Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
payload/platform/plugins/memory/mcp/scripts/graph/accept.shView on unpkg · L20Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
payload/platform/plugins/prompt-optimiser/skills/prompt-optimiser/__tests__/restatement-ladder.test.shView on unpkgPackage ships non-JavaScript build or shell helper files.
payload/platform/plugins/prompt-optimiser/skills/prompt-optimiser/__tests__/restatement-ladder.test.shView on unpkgPackage ships high-entropy non-source blobs.
payload/server/public/assets/src-BvINb2fL.js.gzView on unpkgPackage ships compressed or archive-like blobs.
payload/server/public/assets/src-BvINb2fL.js.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
payload/platform/plugins/memory/mcp/dist/tools/memory-read-attachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/brew-install.jsView on unpkgPackage contains a possible secret pattern.
payload/platform/scripts/smoke-boot-services.shView on unpkg · L349Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
payload/platform/plugins/prompt-optimiser/skills/prompt-optimiser/__tests__/restatement-ladder.test.shView on unpkgPackage ships non-JavaScript build or shell helper files.
payload/platform/plugins/prompt-optimiser/skills/prompt-optimiser/__tests__/restatement-ladder.test.shView on unpkgPackage ships high-entropy non-source blobs.
payload/server/public/assets/src-BvINb2fL.js.gzView on unpkgPackage ships compressed or archive-like blobs.
payload/server/public/assets/src-BvINb2fL.js.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
payload/platform/plugins/memory/mcp/dist/tools/memory-read-attachment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/brew-install.jsView on unpkgSource downloads or fetches remote code and executes it.
dist/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/index.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/index.jsView on unpkg · L142A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L285Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
payload/platform/plugins/memory/mcp/scripts/graph/accept.shView on unpkg · L20