WebWork abilities for opencode
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically changes persistent OpenCode-related environment configuration. No data theft or remote execution was identified in the inspected executable source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package automatically runs its post-install script.
package.jsonView on unpkg · L58Package ships non-JavaScript build or shell helper files.
skills/pytest/references/src/pytest-sample/UserService.pyView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/index.jsView on unpkgThis report applies to @wwkit/harness@1.0.32.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L59Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L59The package automatically runs its post-install script.
package.jsonView on unpkg · L58Package ships non-JavaScript build or shell helper files.
skills/pytest/references/src/pytest-sample/UserService.pyView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/index.jsView on unpkg