TechieFlow: a spec-driven development framework for AI coding agents, for Claude Code and OpenCode. One command installs it into any project.
LPM flags this version as an AI-agent control-surface risk. The npm postinstall hook automatically changes the consumer project's AI-agent controls. It creates broad Claude Code permissions and deploys OpenCode configuration and plugins without specific consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.tfcore/utils/tf-goal.shView on unpkgPackage ships non-JavaScript build or shell helper files.
.tfcore/utils/tf-goal.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/install.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.mjsView on unpkgThis report applies to @techierathore/techieflow@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L45Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.tfcore/utils/tf-goal.shView on unpkgPackage ships non-JavaScript build or shell helper files.
.tfcore/utils/tf-goal.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/install.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install.mjsView on unpkg