Claude Code Hook -> 本地常驻 Daemon 的状态/持久化底座
LPM treats this as warn-only first-party agent extension lifecycle risk. An explicit `shine-worklog install` deploys and enables this package as a Claude Code plugin, whose hooks collect Claude event data into a local daemon. The daemon can silently update itself from npm; hook startup can install Bun if absent.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/hook/main.tsView on unpkgPackage source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/hook/main.tsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.cjsView on unpkg