Thin control plane for Codex, Claude Code, OpenCode, and Pi agent sessions: run, steer, observe, and a live TUI with diffs.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically downloads and runs a native executable, which installs an agent skill into shared user-level Claude and agent skill directories. This changes AI-agent behavior without an explicit user setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.cjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/npm-binary.cjsView on unpkgThis report applies to ruddr@0.3.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.cjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/npm-binary.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L58Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5