screenpipe CLI — AI that knows everything you've seen, said, or heard
npm installation automatically downloads and places an executable in the user's local bin directory or attempts privileged system package installation. It also transmits install telemetry containing host identity and selected package-specific environment values.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L5A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
scripts/postinstall.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/postinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cli.jsView on unpkgThis report applies to screenpipe@0.4.41.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L13Package ships non-JavaScript build or shell helper files.
scripts/postinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cli.jsView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L5A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
scripts/postinstall.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg