Mission control for your Claude Code fleet — installs the Francois desktop app without an installer.
Automatic install-time delivery of an unsigned native application designed to evade browser-origin security controls. The payload is persisted and registered with OS launch surfaces.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/francois.jsView on unpkg · L11Package source invokes a package manager install command at runtime.
bin/francois.jsView on unpkg · L113A single source file combines environment access, network access, and code or shell execution; review context before blocking.
install.js#virtual:normalized:round1View on unpkg · L114Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/desktop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/francois.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/francois.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L26Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L19A single source file combines environment access, network access, and code or shell execution; review context before blocking.
install.js#virtual:normalized:round1View on unpkg · L114Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/desktop.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/francois.jsView on unpkg · L11Package source invokes a package manager install command at runtime.
bin/francois.jsView on unpkg · L113Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/francois.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/francois.jsView on unpkg