Screenata CLI — compliance workflows from your terminal
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically creates and links or overwrites AI-agent skill files. It targets detected Claude Code, Codex, OpenCode, and OpenClaw installations.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L166Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/cli.jsView on unpkg · L3914Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/postinstall.jsView on unpkgThis report applies to @screenata/cli@0.5.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L21Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/postinstall.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L166Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/cli.jsView on unpkg · L3914