Screenata CLI — compliance workflows from your terminal
LPM flags this version as an AI-agent control-surface risk. npm installation silently modifies detected AI-agent skill locations. It establishes a Screenata instruction file and links/copies it into multiple third-party agent control surfaces.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L142Package source references a known benign dynamic code generation pattern.
dist/cli.jsView on unpkg · L3877Package source references dynamic require/import behavior.
dist/postinstall.jsView on unpkg · L516Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L21Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L142Package source references a known benign dynamic code generation pattern.
dist/cli.jsView on unpkg · L3877Package source references dynamic require/import behavior.
dist/postinstall.jsView on unpkg · L516