AI-native spec-driven development framework for Claude Code, Pi, and Codex
LPM treats this as warn-only first-party agent extension lifecycle risk. On npm install, postinstall runs the package installer. In CI, and when stdin closes without a TTY choice, it selects Claude Code and copies this package's agent, command, skill, and rule files into the consumer project's harness directory, overwriting an existing agents folder, and it also writes AGENTS.md and a .gitignore entry.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe npm postinstall script runs node .catalyst/bin/install.js, and that file calls install() as soon as it loads.
package.jsonView on unpkg · L5Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
.catalyst/bin/install.jsView on unpkg · L34Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
.catalyst/bin/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.catalyst/bin/install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
.catalyst/bin/install.jsView on unpkgWhen CI is set, harness selection returns claude with no prompt; a closed non-interactive stdin also falls through to claude.
.catalyst/bin/install.jsView on unpkg · L102When CI is set, harness selection returns claude with no prompt; a closed non-interactive stdin also falls through to claude.
.catalyst/bin/install.jsView on unpkg · L437A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
.catalyst/bin/install.js#virtual:normalized:round1View on unpkgThis report applies to catalyst-os@3.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L5The npm postinstall script runs node .catalyst/bin/install.js, and that file calls install() as soon as it loads.
package.jsonView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
.catalyst/bin/install.js#virtual:normalized:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
.catalyst/bin/install.jsView on unpkg · L34When CI is set, harness selection returns claude with no prompt; a closed non-interactive stdin also falls through to claude.
.catalyst/bin/install.jsView on unpkg · L102When CI is set, harness selection returns claude with no prompt; a closed non-interactive stdin also falls through to claude.
.catalyst/bin/install.jsView on unpkg · L437Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
.catalyst/bin/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.catalyst/bin/install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
.catalyst/bin/install.jsView on unpkg