Claude Code Hook -> 本地常驻 Daemon 的状态/持久化底座
Static analysis flagged 20 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkgPackage source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/daemonctl.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/daemonctl.tsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkg