火山方舟 ARK 平台命令行工具
On installation, the package fetches and executes an opaque native binary. It then automatically asks that binary to refresh and install skills into local AI agents.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs a postinstall hook automatically.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgThe install hook automatically runs the downloaded binary with +connect --refresh to install skills into detected agents.
scripts/postinstall.jsView on unpkg · L328This report applies to @volcengine/ark-cli@1.0.29.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L14The package runs a postinstall hook automatically.
package.jsonView on unpkg · L13The install hook automatically runs the downloaded binary with +connect --refresh to install skills into detected agents.
scripts/postinstall.jsView on unpkg · L328Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg