Enforce AI agent skills before every file edit: prompt classifier, skill catalog, and pre-edit gate.
LPM flags this version as an AI-agent control-surface risk. An automatic npm postinstall changes the user's OpenCode control surface without confirmation. It also removes unrelated globally installed MCP packages when found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
mcp/argus/tmp/argus/argus-results-1791138636150.jsonView on unpkg · L11Stripe test secret key in mcp/argus/tmp/argus/argus-results-1791138636150.json
mcp/argus/tmp/argus/argus-results-1791138636150.jsonView on unpkg · L11This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/novahiz.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/novahiz.mjsView on unpkg · L64Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install/bootstrap.mjsView on unpkg · L5Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install/install.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
install/install.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
mcp/argus/src/test/test_vulnerable.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/memory.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/llm-threat-review/scripts/llm_risk_lint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/secrets-hygiene/scripts/secret_scan.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/skill-authoring/scripts/skill_frontmatter_lint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/skill-eval-loop/scripts/skill_structure_check.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/ui-slop-remover/scripts/slop_lint.mjsView on unpkgThis report applies to novahiz@0.4.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L55Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L55Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install/install.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
install/install.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
mcp/argus/src/test/test_vulnerable.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/memory.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/llm-threat-review/scripts/llm_risk_lint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/secrets-hygiene/scripts/secret_scan.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/skill-authoring/scripts/skill_frontmatter_lint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/skill-eval-loop/scripts/skill_structure_check.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/ui-slop-remover/scripts/slop_lint.mjsView on unpkgPackage contains a high-severity secret pattern.
mcp/argus/tmp/argus/argus-results-1791138636150.jsonView on unpkg · L11Stripe test secret key in mcp/argus/tmp/argus/argus-results-1791138636150.json
mcp/argus/tmp/argus/argus-results-1791138636150.jsonView on unpkg · L11Package source references dynamic require/import behavior.
bin/novahiz.mjsView on unpkg · L64This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/novahiz.mjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install/bootstrap.mjsView on unpkg · L5