Super Audit(SA)工程方法包安装器:自动探测已装宿主,将完整 assistant Skill 目录安装到宿主官方 Skill 目录
LPM flags this version as an AI-agent control-surface risk. On npm install, postinstall unconditionally runs the bundled installer with the install argument. That installer is described as probing several coding-agent hosts and writing a complete assistant skill directory into each host official skill directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgnpm install runs postinstall, which executes node bin/postinstall.js with no user prompt.
package.jsonView on unpkg · L9Package metadata and README state that install detects Codex, Claude Code, and OpenCode and writes a full assistant skill tree into each host official skill directory.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgThe shim selects a bundled platform binary and runs it with the forwarded arguments, so install reaches the opaque installer.
bin/super-audit.jsView on unpkg · L32postinstall always spawns bin/super-audit.js with the install argument.
bin/postinstall.jsView on unpkg · L7This report applies to super-audit@0.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package metadata and README state that install detects Codex, Claude Code, and OpenCode and writes a full assistant skill tree into each host official skill directory.
package.jsonView on unpkg · L4Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10npm install runs postinstall, which executes node bin/postinstall.js with no user prompt.
package.jsonView on unpkg · L9The shim selects a bundled platform binary and runs it with the forwarded arguments, so install reaches the opaque installer.
bin/super-audit.jsView on unpkg · L32Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgpostinstall always spawns bin/super-audit.js with the install argument.
bin/postinstall.jsView on unpkg · L7