AI called this Suspicious at 88.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- Explicit CLI scaffolds Claude Code skills into the selected root.
- When uv is available, generated MCP config runs uvx from a pinned GitLab source.
- The bundled vault MCP can access credentials in its own macOS Keychain service.
Evidence against
- package.json has no install, preinstall, or postinstall hook.
- All setup follows explicit `npm create stead` invocation and selected root path.
- No source evidence of credential exfiltration, stealth, or destructive foreign-file mutation.
Behavioral surface
SourceChildProcessCryptoEnvironmentVarsFilesystemNetworkShell
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 56 file(s), 444 KB of source, external domains: claude.com, docs.astral.sh, fonts.googleapis.com, fonts.gstatic.com, gitlab.com