Detector libraryPackage install scripts

Package install scripts

Install the package. Run its script.

See executable lifecycle hooks before overlooking them in a manifest.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

Your agent installs a dependency. The package manifest also names a script that runs during installation. What looks like setup can include code execution that deserves its own review.

A project may use install hooks for perfectly ordinary build steps. It may also contain an unexpected command. The important point is that the script lives in the manifest, where it can be missed if you only inspect the top level install command.

What ClawMetry detects

ClawMetry scans the workspace package manifest for supported install lifecycle hooks. It raises a package manifest execution warning and identifies the hook. The scanner reads the file; it does not execute the command it finds.

The difference that changes the finding

Triggering example

postinstall: node build.js

Warning finding

Quiet comparison

test: node build.js

No finding for this detector.

The checked example has a postinstall script that names a build program and produces a warning. Put the same program under an ordinary test script, and this detector stays quiet. The distinction is when the manifest says the program will run.

Inspect the detector result
{
  "kind": "package_manifest_exec",
  "severity": "warning",
  "evidence": {
    "hooks": [
      "postinstall"
    ],
    "hits": [
      {
        "hook": "postinstall",
        "command": "node build.js",
        "tool": null,
        "alarm": null
      }
    ],
    "manifest": "package.json",
    "tools": [],
    "observed": "package_manifest"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Read the hook command and the program it references. Check whether that install behavior belongs in the project and whether the dependency source is trusted. If installation already happened, review the actual effects separately before accepting the environment.

  1. Read the lifecycle hook
  2. Inspect the referenced program
  3. Review expected install behavior

What this signal establishes

An install hook is not automatically hostile. This finding reports the manifest entry, not proof that installation or execution occurred.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.