NanoCorp CLI: create and run your autonomous company from the terminal.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically runs an opaque bundled skill installer. It targets identifiers associated with multiple coding-agent control surfaces.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers an automatic post-install hook.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe bundled executable contains identifiers for several third-party coding-agent directories, indicating a broad agent control surface.
vendor/nanocorp-darwin-arm64View on unpkg · L6396Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe post-install hook launches the bundled executable with a quiet skill-install command unless an environment opt-out is already set.
scripts/postinstall.jsView on unpkg · L9This report applies to nanocorp@0.3.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16The package registers an automatic post-install hook.
package.jsonView on unpkg · L15The bundled executable contains identifiers for several third-party coding-agent directories, indicating a broad agent control surface.
vendor/nanocorp-darwin-arm64View on unpkg · L6396Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe post-install hook launches the bundled executable with a quiet skill-install command unless an environment opt-out is already set.
scripts/postinstall.jsView on unpkg · L9