Git status badges for DeepSeek Harness: an input-row chip on every install, plus sidebar session-row badges (git status, PR/CI action tokens) after one manual step: `npx dsh-git-badge apply`, then restart dsh web. Event-driven freshness over SSE.
LPM flags this version as an AI-agent control-surface risk. Installation automatically changes a separate DeepSeek Harness host package and adds a user-level agent skill. This is an unconsented lifecycle mutation of an AI-agent control surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
seam/postinstall.jsView on unpkg · L23Package source invokes a package manager install command at runtime.
seam/postinstall.jsView on unpkg · L23Source file is highly similar to a previously finalized malicious package; route for source-aware review.
seam/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
seam/apply.jsView on unpkgThis report applies to dsh-git-badge@0.16.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
seam/apply.jsView on unpkgPackage source references child process execution.
seam/postinstall.jsView on unpkg · L23Package source invokes a package manager install command at runtime.
seam/postinstall.jsView on unpkg · L23Source file is highly similar to a previously finalized malicious package; route for source-aware review.
seam/postinstall.jsView on unpkg