ShuvGrok: bring Grok into your terminal
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically mutates the shared upstream Grok home. It places a sibling-package binary there and persists installer/registry settings in the shared config.
Package defines install-time lifecycle scripts.
package.jsonView on unpkg`postinstall` runs automatically on npm install.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkgInstall code deliberately uses the upstream Grok home and shared config path.
bin/postinstall.jsView on unpkg · L9The lifecycle hook writes `cli.installer` and a registry value into `~/.grok/config.toml`.
bin/postinstall.jsView on unpkg · L199It silently installs a compressed sibling-package binary into `~/.grok/bin`.
bin/postinstall.jsView on unpkg · L71Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/shuvgrokView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L26`postinstall` runs automatically on npm install.
package.jsonView on unpkg · L25Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/shuvgrokView on unpkgInstall code deliberately uses the upstream Grok home and shared config path.
bin/postinstall.jsView on unpkg · L9It silently installs a compressed sibling-package binary into `~/.grok/bin`.
bin/postinstall.jsView on unpkg · L71The lifecycle hook writes `cli.installer` and a registry value into `~/.grok/config.toml`.
bin/postinstall.jsView on unpkg · L199Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkg