Super Audit(SA)工程方法包与 Codex 插件:自动探测宿主并完成安装
LPM treats this as warn-only first-party agent extension lifecycle risk. An automatic installation hook invokes an opaque bundled native program in setup mode. This is a package-owned plugin setup path, but no confirmed malicious action was established from the inspected source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package has an automatic post-install hook.
package.jsonView on unpkg · L6Package ships non-JavaScript build or shell helper files.
skills/super-audit/references/methods/workflow-orchestrator/scripts/validate_workflow.pyView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgThe command shim executes a bundled native binary.
bin/super-audit.jsView on unpkg · L40The hook launches the package command with the setup argument.
bin/postinstall.jsView on unpkg · L7This report applies to super-audit@6.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10The package has an automatic post-install hook.
package.jsonView on unpkg · L6Package ships non-JavaScript build or shell helper files.
skills/super-audit/references/methods/workflow-orchestrator/scripts/validate_workflow.pyView on unpkgThe command shim executes a bundled native binary.
bin/super-audit.jsView on unpkg · L40Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgThe hook launches the package command with the setup argument.
bin/postinstall.jsView on unpkg · L7