Stable terminal UI for Codex and Claude Agent SDK
LPM flags this version as an AI-agent control-surface risk. Installing the package runs a postinstall script that writes this package's agent skills into both the Codex and Claude user skill directories. The copy replaces those skill folders and removes files that are not part of the bundle.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-skills.mjsView on unpkg · L1Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/insane-search/tests/live_benchmark/bench.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/insane-search/tests/live_benchmark/bench.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/dvz.jsView on unpkgThis report applies to devez-vibe@1.9.33.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L45Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L45Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/insane-search/tests/live_benchmark/bench.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/insane-search/tests/live_benchmark/bench.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bridge/claude-agent-sdk-bridge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/dvz.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install-skills.mjsView on unpkg · L1