World of Warcraft memory reading tool: read live process memory and versioned section files read-only, with streaming section dumps, profiles, build relocation and a machine-level recipe library
LPM treats this as warn-only first-party agent extension lifecycle risk. The automatic postinstall hook invokes a bundled command to install the package's own skill. The inspected source does not reveal where that skill is installed, so a broader control-surface effect is unconfirmed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs a postinstall hook that invokes the bundled executable with a skill installation command unless an environment flag disables it.
package.jsonView on unpkg · L32Package source references dynamic require/import behavior.
bin/script-host.mjsView on unpkg · L109The package runs a postinstall hook that invokes the bundled executable with a skill installation command unless an environment flag disables it.
bin/postinstall.mjsView on unpkg · L5The package ships a first-party wowdump skill, indicating the install action is agent extension setup.
skills/wowdump/SKILL.mdView on unpkg · L1The executable wrapper runs the bundled native binary, but its installation destination and write behavior are not visible in the inspected source.
bin/wowdump.mjsView on unpkg · L7This report applies to wowdump@2.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L36The package runs a postinstall hook that invokes the bundled executable with a skill installation command unless an environment flag disables it.
package.jsonView on unpkg · L32The package ships a first-party wowdump skill, indicating the install action is agent extension setup.
skills/wowdump/SKILL.mdView on unpkg · L1Package source references dynamic require/import behavior.
bin/script-host.mjsView on unpkg · L109The package runs a postinstall hook that invokes the bundled executable with a skill installation command unless an environment flag disables it.
bin/postinstall.mjsView on unpkg · L5The executable wrapper runs the bundled native binary, but its installation destination and write behavior are not visible in the inspected source.
bin/wowdump.mjsView on unpkg · L7