SynDes — a tamper-evident ledger of everything you do in Claude Code, an efficiency score built from it, and a local dashboard that shows you how you actually work. Splits one shared account between the people on it. macOS, Windows and Linux. Zero depende
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically modifies Claude Code's shared settings and installs a persistent hook package in its configuration directory. The hooks observe broad agent events and save their raw payloads locally.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
runtime/paths.mjsView on unpkg · L12Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
runtime/paths.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
collect/git.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/hook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/preflight.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/systemauth.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
notify/linux.mjsView on unpkgThis report applies to syndes@0.3.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L55Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L55A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
collect/git.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/hook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/preflight.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/systemauth.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
notify/linux.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
runtime/paths.mjsView on unpkg · L12Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
runtime/paths.mjsView on unpkg