AI-powered job search pipeline for Codex and OpenCode
LPM blocks this version under the AI-agent control-surface policy. Installing the package executes a postinstall hook that changes the consumer project's AI-agent configuration surface. It adds package-controlled symlinks and config mutations that can affect future Codex, Claude, Cursor, and OpenCode sessions.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
config/profile.example.ymlView on unpkg · L53Hardcoded password in config/profile.example.yml
config/profile.example.ymlView on unpkg · L124Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/create-job-forge.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/create-job-forge.mjsView on unpkg · L215Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
scripts/receipts.mjsView on unpkg · L417Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/sync.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
batch/batch-runner.shView on unpkgPackage ships high-entropy non-source blobs.
fonts/space-grotesk-latin.woff2View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/geometra-mcp-launcher.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/job-forge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
merge-tracker.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/apply-queue.mjsView on unpkgHardcoded password in modes/reference-portals.md
modes/reference-portals.mdView on unpkg · L68Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L137Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/sync.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
batch/batch-runner.shView on unpkgPackage ships high-entropy non-source blobs.
fonts/space-grotesk-latin.woff2View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/geometra-mcp-launcher.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/job-forge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
merge-tracker.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/apply-queue.mjsView on unpkgPackage contains a possible secret pattern.
config/profile.example.ymlView on unpkg · L53Hardcoded password in config/profile.example.yml
config/profile.example.ymlView on unpkg · L124Package source references dynamic require/import behavior.
bin/create-job-forge.mjsView on unpkg · L215Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/create-job-forge.mjsView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
scripts/receipts.mjsView on unpkg · L417Hardcoded password in modes/reference-portals.md
modes/reference-portals.mdView on unpkg · L68