Volter Harness: a lightweight, customizable AI coding agent CLI — any model via OpenRouter; natively continues Claude Code and Codex sessions.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can invoke native migration of an existing Supercode Teams service. Guards restrict activation to the machine's active installation and matching first-party service units; no confirmed malicious attack was established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs lib/release.mjs after installation.
package.jsonView on unpkg · L13Package source references dynamic require/import behavior.
bin/supercode.jsView on unpkg · L7The hook requires a package-local Teams entry and verifies that this installation is the machine's active Supercode command.
lib/release.mjsView on unpkg · L45The hook requires a package-local Teams entry and verifies that this installation is the machine's active Supercode command.
lib/release.mjsView on unpkg · L34It checks narrowly named Supercode Teams service units for references to another Teams installation.
lib/release.mjsView on unpkg · L14This report applies to @volter/supercode@0.5.224.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13package.json automatically runs lib/release.mjs after installation.
package.jsonView on unpkg · L13Package source references dynamic require/import behavior.
bin/supercode.jsView on unpkg · L7It checks narrowly named Supercode Teams service units for references to another Teams installation.
lib/release.mjsView on unpkg · L14The hook requires a package-local Teams entry and verifies that this installation is the machine's active Supercode command.
lib/release.mjsView on unpkg · L34The hook requires a package-local Teams entry and verifies that this installation is the machine's active Supercode command.
lib/release.mjsView on unpkg · L45