Thin control plane for Codex, Claude Code, OpenCode, Pi, and Factory Droid agent sessions: run, steer, observe, and a live TUI and web dashboard with diffs. One native binary.
LPM treats this as warn-only first-party agent extension lifecycle risk. The npm postinstall hook provisions Ruddr and automatically installs its package-owned delegate skill. This is a guarded first-party agent extension setup risk; no confirmed malicious attack surface was established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4The package runs a postinstall hook that invokes its own binary to install a Ruddr skill.
package.jsonView on unpkg · L49Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5The package runs a postinstall hook that invokes its own binary to install a Ruddr skill.
scripts/npm-postinstall.cjsView on unpkg · L13This report applies to ruddr@0.6.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L4Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L49The package runs a postinstall hook that invokes its own binary to install a Ruddr skill.
package.jsonView on unpkg · L49Package source references dynamic require/import behavior.
bin/ruddr.cjsView on unpkg · L5The package runs a postinstall hook that invokes its own binary to install a Ruddr skill.
scripts/npm-postinstall.cjsView on unpkg · L13