Internal tool.
LPM flags this version as an AI-agent control-surface risk. The package performs install-time writes into local AI agent skill directories. This creates or updates agent instructions from a package lifecycle hook without explicit user invocation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source drops package-supplied AI-agent/MCP control files or instructions.
bin/install-skills.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L42Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L588This report applies to @studyfetch/sfdeploy@0.7.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Install-time source drops package-supplied AI-agent/MCP control files or instructions.
bin/install-skills.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L42Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L588