Schema validation package for CXTMS YAML modules
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically modifies the consumer project's Claude Code skill directory. No credential theft, network activity, or remote payload execution was identified in the inspected postinstall path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
templates/workflow-ftp-edi.yamlView on unpkg · L62Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L1545Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1Hardcoded password in templates/workflow-ftp-tracking.yaml
templates/workflow-ftp-tracking.yamlView on unpkg · L62This report applies to cxtms@1.9.259.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L14Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1Package contains a possible secret pattern.
templates/workflow-ftp-edi.yamlView on unpkg · L62Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L1545Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgHardcoded password in templates/workflow-ftp-tracking.yaml
templates/workflow-ftp-tracking.yamlView on unpkg · L62