让任意 AI Agent 直接调用 focalapi 创作模型的命令行工具
LPM flags this version as an AI-agent control-surface risk. npm postinstall automatically runs connect install, which writes bundled FocalAPI skill files into detected third-party agent skill directories under the user home. Those skills tell foreign agents to send creative tasks through this CLI even when the user did not ask for FocalAPI.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material through DNS lookups.
dist/cli.jsView on unpkg · L41A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgThis report applies to focalapi-cli@0.7.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L26Source appears to send environment or credential material through DNS lookups.
dist/cli.jsView on unpkg · L41A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkg