Full observability & control for the Claude product line — Claude Code (local/remote/cloud), claude.ai conversations, Cowork, agents, memory, connectors, usage — via web dashboard, REST API, and MCP tools
LPM flags this version as an AI-agent control-surface risk. A global npm installation automatically starts services and modifies Claude Code integration. It installs a marketplace plugin and configures a status-line command without an explicit user command.
Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
package.jsonView on unpkg · L44Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource matches reverse-shell style process and socket wiring.
core/dist/service-manager.jsView on unpkg · L58A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
core/dist/service-manager.jsView on unpkg · L58Package source references a known benign dynamic code generation pattern.
web/.next/standalone/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L18699Package source references weak cryptographic algorithms.
web/.next/standalone/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39Package source references dynamic require/import behavior.
core/dist/project-summary-store.jsView on unpkg · L47A manifest entrypoint or package-local install chain reaches persistence behavior.
core/dist/routes/core/tmux.routes.jsView on unpkg · L52Source writes installer persistence such as shell profile or service configuration.
core/dist/routes/core/tmux.routes.jsView on unpkg · L52A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/scripts/memory-reconcile.jsView on unpkg · L19Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
web/.next/standalone/node_modules/next/dist/compiled/edge-runtime/index.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/lm-assist.jsView on unpkg · L25A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/lm-assist.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lm-assist.jsPackage source invokes a package manager install command at runtime.
core/scripts/verify-deploy.mjsView on unpkg · L106Package ships native binary artifacts.
web/.next/standalone/node_modules/sharp/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.17.3View on unpkgPackage ships non-JavaScript build or shell helper files.
core/hooks/statusline-worktree.shView on unpkgPackage ships high-entropy non-source blobs.
web/.next/standalone/web/.next/server/app/icon.png.bodyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
web/.next/standalone/web/.next/server/app/icon.png.bodyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
web/.next/standalone/node_modules/typescript/lib/typescript.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/ui-pages/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/cli-runner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/mcp-server/plugins/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/memory/autosync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/memory/harvest-daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/rest-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/routes/core/dev-mode.routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/routes/core/machine-access.routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/ttyd-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/utils/claude-oauth.jsView on unpkgThis report applies to lm-assist@0.2.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
core/dist/service-manager.jsView on unpkg · L58Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
core/dist/service-manager.jsView on unpkg · L58Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
package.jsonView on unpkg · L44Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
web/.next/standalone/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L18699Package source references weak cryptographic algorithms.
web/.next/standalone/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39A manifest entrypoint or package-local install chain reaches persistence behavior.
core/dist/routes/core/tmux.routes.jsView on unpkg · L52Source writes installer persistence such as shell profile or service configuration.
core/dist/routes/core/tmux.routes.jsView on unpkg · L52A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/scripts/memory-reconcile.jsView on unpkg · L19Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
web/.next/standalone/node_modules/next/dist/compiled/edge-runtime/index.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/lm-assist.jsView on unpkg · L25A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/lm-assist.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lm-assist.jsPackage source invokes a package manager install command at runtime.
core/scripts/verify-deploy.mjsView on unpkg · L106Package ships native binary artifacts.
web/.next/standalone/node_modules/sharp/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.17.3View on unpkgPackage ships non-JavaScript build or shell helper files.
core/hooks/statusline-worktree.shView on unpkgPackage ships high-entropy non-source blobs.
web/.next/standalone/web/.next/server/app/icon.png.bodyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
web/.next/standalone/web/.next/server/app/icon.png.bodyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
web/.next/standalone/node_modules/typescript/lib/typescript.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/ui-pages/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/cli-runner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/mcp-server/plugins/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/memory/autosync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/memory/harvest-daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/rest-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/routes/core/dev-mode.routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/routes/core/machine-access.routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/ttyd-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/utils/claude-oauth.jsView on unpkgPackage source references child process execution.
core/dist/service-manager.jsView on unpkg · L58Source matches reverse-shell style process and socket wiring.
core/dist/service-manager.jsView on unpkg · L58A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
core/dist/service-manager.jsView on unpkg · L58Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
core/dist/service-manager.jsView on unpkg · L58Package source references dynamic require/import behavior.
core/dist/project-summary-store.jsView on unpkg · L47