Thin control plane for Codex, Claude Code, OpenCode, Pi, and Factory Droid agent sessions: run, steer, observe, and a live TUI and web dashboard with diffs. One native binary.
LPM treats this as warn-only first-party agent extension lifecycle risk. During npm installation, the package provisions its native binary and runs that binary's first-party skill installer. This is an automatic agent-extension setup path, but inspected source does not establish malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4The npm postinstall hook fetches a platform binary, then automatically runs its first-party `skill install` command.
package.jsonView on unpkg · L46Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5The npm postinstall hook fetches a platform binary, then automatically runs its first-party `skill install` command.
scripts/npm-postinstall.cjsView on unpkg · L10This report applies to ruddr@0.6.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4The npm postinstall hook fetches a platform binary, then automatically runs its first-party `skill install` command.
package.jsonView on unpkg · L46Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L49Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5The npm postinstall hook fetches a platform binary, then automatically runs its first-party `skill install` command.
scripts/npm-postinstall.cjsView on unpkg · L10