WoW native memory analysis CLI with Ghidra, Frida validation, and an elevated reader broker
LPM flags this version as an AI-agent control-surface risk. Installing the package triggers a postinstall routine that writes an AI-agent skill into the user's broad ~/.agents skill directory. It also downloads and extracts native toolchain archives when dependencies are absent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L1Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/toolchain.jsView on unpkg · L50A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent.jsView on unpkgThis report applies to wowdump@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L28Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L28Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/toolchain.jsView on unpkg · L50