Stable terminal UI for Codex and Claude Agent SDK
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies global skill directories for both Codex and Claude. The installed skill can direct later agent sessions to invoke Codex CLI subprocesses.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe npm postinstall hook automatically runs the skill installer.
package.jsonView on unpkg · L40Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-skills.mjsView on unpkg · L1The installer targets global Codex and Claude skill directories under the user's home configuration.
install-skills.mjsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgThis report applies to devez-vibe@1.6.57.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41The npm postinstall hook automatically runs the skill installer.
package.jsonView on unpkg · L40Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgThe installer targets global Codex and Claude skill directories under the user's home configuration.
install-skills.mjsView on unpkg · L14Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-skills.mjsView on unpkg · L1