An AX/FDE harness for Claude Code, Codex CLI and ChatGPT desktop. Say what you need, approve the scenarios once; the harness proves the work by running the checks itself. Memory in plain files, human tokens for irreversible actions, a ledger instead of cl
LPM flags this version as an AI-agent control-surface risk. A global npm install silently modifies Claude, Codex, and Hermes agent homes. It injects instruction cards and skills and registers command hooks.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
mcpb/server/index.jsView on unpkg · L10Package source references weak cryptographic algorithms.
dist/core/tree.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/github.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/github.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/global.jsView on unpkg · L16Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install/plugin.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/docs/pdf.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/checks/eval.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/common.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/check.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install/plugin.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/docs/pdf.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/checks/eval.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/common.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/check.jsView on unpkgPackage source references child process execution.
mcpb/server/index.jsView on unpkg · L10Package source references weak cryptographic algorithms.
dist/core/tree.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/github.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/github.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/global.jsView on unpkg · L16