Volter Harness: a lightweight, customizable AI coding agent CLI — any model via OpenRouter; natively continues Claude Code and Codex sessions.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can trigger a guarded migration of an existing Supercode Teams service through a native dependency. This establishes a package-owned lifecycle risk, but no confirmed malicious attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs lib/release.mjs after installation.
package.jsonView on unpkg · L13Package source references dynamic require/import behavior.
bin/supercode.jsView on unpkg · L7The hook requires a package-local Teams entry and checks that this installation is the machine’s active Supercode.
lib/release.mjsView on unpkg · L47The hook reads matching Supercode Teams service units and invokes a native migration command when their Teams entry differs.
lib/release.mjsView on unpkg · L52The migration executable comes from a platform-specific optional dependency; its implementation is absent from this snapshot.
lib/release.mjsView on unpkg · L65This report applies to @volter/supercode@0.5.223.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13package.json automatically runs lib/release.mjs after installation.
package.jsonView on unpkg · L13Package source references dynamic require/import behavior.
bin/supercode.jsView on unpkg · L7The hook requires a package-local Teams entry and checks that this installation is the machine’s active Supercode.
lib/release.mjsView on unpkg · L47The hook reads matching Supercode Teams service units and invokes a native migration command when their Teams entry differs.
lib/release.mjsView on unpkg · L52The migration executable comes from a platform-specific optional dependency; its implementation is absent from this snapshot.
lib/release.mjsView on unpkg · L65