Clawd Bot — one-shot install for sovereign Solana + Robinhood omni agent runtime: RH skill pack, Skill Hub (train2earn + skillhub-main), agents, packages, clawdbot CLI hooks. Connect at cheshireterminal.ai/zeroclawd
LPM flags this version as an AI-agent control-surface risk. npm postinstall copies bundled SKILL.md files into ~/.clawdbot/skills and force-symlinks them into Claude Code, Codex, and generic agent skill directories. Skip flags are opt-out only, so a normal dependency install mutates foreign agent control surfaces. Those skills include mandatory host-setup instructions for Claude Code and Codex.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/oneshot-install.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/oneshot-install.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
install-npm.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/pump-tape.mjsView on unpkgThis report applies to clawdbot-go@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L79Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L79A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
install-npm.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/pump-tape.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/oneshot-install.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/oneshot-install.mjsView on unpkg