Internal tool.
LPM flags this version as an AI-agent control-surface risk. An npm postinstall writes a package-controlled agent skill into multiple unrelated user-wide agent control surfaces. The installed skill broadly intercepts deployment requests and instructs agents to keep this package updated.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install-skills.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L46This report applies to @studyfetch/sfdeploy@0.11.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install-skills.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L46This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg