Super Audit(SA)工程方法包与 Codex 插件:自动探测宿主并完成安装
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically launches opaque native setup code for a plugin with read and write capabilities. No confirmed network or credential attack was established from the inspected source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package registers a postinstall lifecycle hook.
package.jsonView on unpkg · L8Package ships non-JavaScript build or shell helper files.
skills/super-audit/references/methods/workflow-orchestrator/scripts/validate_workflow.pyView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgThe shim forwards setup to a platform-native executable.
bin/super-audit.jsView on unpkg · L42The postinstall hook automatically invokes setup through the command shim.
bin/postinstall.jsView on unpkg · L8This report applies to super-audit@6.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10The package registers a postinstall lifecycle hook.
package.jsonView on unpkg · L8Package ships non-JavaScript build or shell helper files.
skills/super-audit/references/methods/workflow-orchestrator/scripts/validate_workflow.pyView on unpkgThe shim forwards setup to a platform-native executable.
bin/super-audit.jsView on unpkg · L42Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/super-audit.jsView on unpkgThe postinstall hook automatically invokes setup through the command shim.
bin/postinstall.jsView on unpkg · L8