A meta-prompting, context engineering and spec-driven development system for Claude Code by Projecta.ai
LPM flags this version as an AI-agent control-surface risk. Installing the package runs a postinstall script that globally rewrites the user's Claude Code control surface. It copies the toolkit into ~/.claude, wires tool hooks into settings.json, and registers an MCP server.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/hosted-setup.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/hosted-setup.jsView on unpkgPackage source references dynamic require/import behavior.
bin/hosted-setup.jsView on unpkg · L23Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install.jsView on unpkg · L135Package source references weak cryptographic algorithms.
rrr/lib/search/index-manifest.jsView on unpkg · L51Package ships non-JavaScript build or shell helper files.
hooks/rrr-update-cache-stats.shView on unpkgPackage ships compressed or archive-like blobs.
rrr/skills/upstream/anthropic/web-artifacts-builder/scripts/shadcn-components.tar.gzView on unpkgPackage ships high-entropy non-source blobs.
rrr/skills/upstream/anthropic/theme-factory/theme-showcase.pdfView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/cdp-browser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/vitest-browser-ai.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/zeroshot-validator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/mcp/discovery.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/team-mode/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap-external-skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/security-gate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/hooks/session-start.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/mcp/validate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/savings/harness.jsView on unpkgThis report applies to projecta-rrr@1.25.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/install.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
bin/install.jsView on unpkg · L23Package source invokes a package manager install command at runtime.
bin/install.jsView on unpkg · L1098A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/install.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
bin/install.jsView on unpkg · L23Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10Package ships non-JavaScript build or shell helper files.
hooks/rrr-update-cache-stats.shView on unpkgPackage ships compressed or archive-like blobs.
rrr/skills/upstream/anthropic/web-artifacts-builder/scripts/shadcn-components.tar.gzView on unpkgPackage ships high-entropy non-source blobs.
rrr/skills/upstream/anthropic/theme-factory/theme-showcase.pdfView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/cdp-browser.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/vitest-browser-ai.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/uat/zeroshot-validator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/mcp/discovery.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/team-mode/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap-external-skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/security-gate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/hooks/session-start.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/mcp/validate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
rrr/lib/savings/harness.jsView on unpkgPackage source references dynamic require/import behavior.
bin/hosted-setup.jsView on unpkg · L23Package source references child process execution.
bin/hosted-setup.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/hosted-setup.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
bin/install.jsView on unpkg · L23Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/install.jsView on unpkg · L135Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/install.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
bin/install.jsView on unpkg · L23Package source invokes a package manager install command at runtime.
bin/install.jsView on unpkg · L1098A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/install.jsView on unpkgPackage source references weak cryptographic algorithms.
rrr/lib/search/index-manifest.jsView on unpkg · L51