Is @hasna/projects safe?
- Node.js shell/command execution
- npm install-time lifecycle hook
- Node.js filesystem read
What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.
@hasna/projects is an npm package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 1 risky construct is reported for review. It can: delegated authentication, filesystem read, filesystem write, install time execution, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 10/100 (low).
@hasna/projects 1.3.0
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of @hasna/projects's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (8)
package.json runs scripts automatically when the package is installed.
"postinstall": "mkdir -p $HOME/.hasna/projects 2>/dev/null || true",
Why it matters: Install scripts are a favorite supply-chain foothold — they execute on every machine that installs the package.
Fix: Inspect the hook command. Install-time scripts are a common supply chain execution vector; ensure they do nothing beyond a documented build step.
The component can run operating-system commands or spawn processes.
const result = Bun.spawnSync({spawnSync: (options) => Bun.spawnSync(options),
const proc = Bun.spawn({const result = Bun.spawnSync({import { execFileSync as execFileSync2 } from "child_process";import { execFileSync } from "child_process";import { execFileSync as execFileSync3 } from "child_process";import { execFileSync as execFileSync4 } from "child_process";import { execFileSync as execFileSync5 } from "child_process";const result = Bun.spawnSync({import { spawnSync } from "child_process";const result = spawnSync(KEYCHAIN_SECURITY_BIN, [...argv], {const result = Bun.spawnSync({Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.
The component ships agent or IDE configuration that executes a command without a separate step: a Claude Code / Gemini CLI / Cursor hook, or a VS Code task that runs when the folder opens. Opening the project in that tool runs it with the developer's privileges.
"command": ".cursor/hooks/goal-continue.sh",
Fix: Read the command and anything it runs before opening this project in an agent or editor. A published package has no reason to ship project auto-run config.
The component reads files from disk.
const content = fs.readFileSync(authPath, "utf8");
const prj = JSON.parse(fs.readFileSync(prjPath, "utf8"));
const token = JSON.parse(fs.readFileSync(tokenPath, "utf8"));
Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component writes or deletes files on disk.
fs.writeFileSync(authPath, JSON.stringify(config2, null, 2), { mode: 384 });fs.writeFileSync(tokenPath, tokenJson);
Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.
Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.
The component makes outbound network requests.
const response = await fetch(discoveryUrl, {return await fetch(tokenEndpoint, {const res = await fetch(url2, {async fetch(req) {/** Custom fetch (defaults to global fetch). */
Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
An OAuth 2.0 / OpenID Connect delegated-authentication flow was detected (authorization-code / refresh-token / token-exchange grant, an OIDC authorize/discovery endpoint or id_token, or a delegation library). Tools authenticate with the end user's delegated, scoped credentials rather than a long-lived embedded service credential. (2 occurrence(s) shown as evidence).
const discoveryUrl = `${VERCEL_ISSUER}/.well-known/openid-configuration`;grant_type: "refresh_token",
Fix: Delegated auth is a lower-blast-radius execution context than an embedded static credential. Confirm the requested scopes are minimal and that tokens are never logged or forwarded off-host.
An MCP tool surface (manifest or tool definitions) was found.
server.tool("projects_projection_issue", "Issue one historical ProductProjection receipt. Requires server policy; grants no deployment authority.", { project_id: exports_external.string(), request: ProjectionIssueSchema }, async ({ project_ …server.tool("projects_projection_get", "Read an exact authorized immutable ProductProjection receipt.", { project_id: exports_external.string(), receipt_id: exports_external.string(), ...ProjectionReadSchema.shape }, async ({ project_id, re …const server = new McpServer({server.tool("projects_roots_list", "List registered root folders and path templates for projects. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_roots_add", "Register a root folder that projects can be created under.", {server.tool("projects_roots_show", "Show one registered root by id or slug.", { id: exports_external.string() }, async (input) => {server.tool("projects_roots_update", "Update a registered root folder and its defaults.", {server.tool("projects_roots_delete", "Delete a registered root. Refuses roots referenced by projects unless detach_projects=true.", {server.tool("projects_roots_match", "Score and match registered roots by path, kind, tags, and GitHub org.", {server.tool("projects_recipes_list", "List project recipes for agent-visible creation defaults. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_recipes_add", "Register a project recipe with optional default tags and JSON steps.", {server.tool("projects_recipes_built_ins", "List built-in project recipe definitions. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_recipes_seed_defaults", "Create any missing built-in project recipes.", {}, async () => {server.tool("projects_agents_list", "List registered agents, or agents assigned to a specific project. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_agents_add", "Register a human, CLI, service, or AI agent for project attribution.", {server.tool("projects_agents_assign", "Assign a registered agent to a project role and record an audit event.", {server.tool("projects_tmux_profiles_list", "List saved project tmux profiles. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_tmux_profiles_add", "Create a saved tmux profile with optional windows.", {server.tool("projects_tmux_profiles_apply", "Apply a saved tmux profile to a project.", {server.tool("projects_list", "List registered projects across all roots and arbitrary paths. Full records by default; pass compact=true for compact summaries.", {server.tool("projects_search", "Search registered projects with a compact bounded page by default. Searches discovery fields unless query_scope is explicit; use projects_show for full detail. Legacy projects_list remains unchanged.", {server.tool("projects_show", "Show a project with locations and event history. Full records by default; pass compact=true for a compact summary.", {server.tool("projects_render_list", "Return a validated JSON Render spec for the projects list surface.", {server.tool("projects_render_show", "Return a validated JSON Render spec for one project detail surface.", { id: exports_external.string() }, async (input) => {server.tool("projects_render_sessions", "Return a validated JSON Render spec for recent project start sessions.", { project: exports_external.string(), limit: exports_external.number().int().positive().max(100).optional(), unrenamed: export …Why it matters: Just context — review which tools it offers and their permissions.
Fix: Review the declared MCP tools and their permissions.
How attackers abuse these capabilities
Interactive labs on the attack class behind the rules above. They show the technique, not anything found in @hasna/projects.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →