MCP launcher for brokre — local credential broker for Cursor, Claude Code, Kimi Code, Trae, OpenClaw, Hermes Agent, ChatClaw, and other MCP clients
LPM flags this version as an AI-agent control-surface risk. The npm postinstall hook automatically registers brokre as an MCP server in detected client configuration files. This changes global AI-client control configuration without a consent prompt.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
index.jsView on unpkg · L9Source writes installer persistence such as shell profile or service configuration.
index.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
postinstall.jsView on unpkg · L15This report applies to brokre@0.2.32.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L29A manifest entrypoint or package-local install chain reaches persistence behavior.
index.jsView on unpkg · L9Source writes installer persistence such as shell profile or service configuration.
index.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
postinstall.jsView on unpkg · L15