Thin control plane for Codex, Claude Code, OpenCode, and Pi agent sessions: run, steer, observe, and a live TUI with diffs.
LPM flags this version as an AI-agent control-surface risk. On npm installation, the package fetches or builds and executes a binary that installs a Ruddr agent skill into home-level Claude and agent skill directories. This mutates broad AI-agent control surfaces without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tui/core.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-binary.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/npm-binary.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
opencode/runtime.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
opencode/runtime.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tui/core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi/runtime.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tui/git.tsView on unpkgThis report applies to ruddr@0.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tui/core.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-binary.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/npm-binary.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
opencode/runtime.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
opencode/runtime.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/npm-postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tui/core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi/runtime.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tui/git.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L58Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5