Internal tool.
LPM flags this version as an AI-agent control-surface risk. The postinstall hook silently installs a package-controlled skill into multiple unrelated AI-agent user directories. That changes future agent behavior without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install-skills.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L46This report applies to @studyfetch/sfdeploy@0.10.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install-skills.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L46This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg