SkillTotal

Is @hasna/projects safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Node.js shell/command execution
  • npm install-time lifecycle hook
  • Node.js filesystem read

What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.

@hasna/projects is an npm package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 1 risky construct is reported for review. It can: delegated authentication, filesystem read, filesystem write, install time execution, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 10/100 (low).

@hasna/projects 1.3.0

npm_package · npm:@hasna/projects
LOW
10
/ 100 risk score
Snapshot · scanned Oct 7, 2026 · @hasna/projects@1.3.0 · engine 0.56.2 / ruleset 62

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of @hasna/projects's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
delegated authenticationfilesystem readfilesystem writeinstall time executionmcp tools detectednetwork egressshell execution

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Tool surface
Tool Usage
Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication
Delegated authentication
Tool Execution Context / User Delegated Credentials
Supply-chain provenance risk
General Protections / Supply Chain

Findings (8)

HIGHnpm install-time lifecycle hookST-INSTALL-NPM

package.json runs scripts automatically when the package is installed.

"postinstall": "mkdir -p $HOME/.hasna/projects 2>/dev/null || true",

Why it matters: Install scripts are a favorite supply-chain foothold — they execute on every machine that installs the package.

Fix: Inspect the hook command. Install-time scripts are a common supply chain execution vector; ensure they do nothing beyond a documented build step.

HIGHNode.js shell/command executionST-SHELL-NODE

The component can run operating-system commands or spawn processes.

const result = Bun.spawnSync({
spawnSync: (options) => Bun.spawnSync(options),
const result = Bun.spawnSync({
import { execFileSync as execFileSync2 } from "child_process";
import { execFileSync } from "child_process";
import { execFileSync as execFileSync3 } from "child_process";
import { execFileSync as execFileSync4 } from "child_process";
import { execFileSync as execFileSync5 } from "child_process";
const result = Bun.spawnSync({
import { spawnSync } from "child_process";
const result = spawnSync(KEYCHAIN_SECURITY_BIN, [...argv], {
const result = Bun.spawnSync({

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.

MEDIUMAgent or editor configuration runs a command automaticallyST-AGENT-AUTORUN

The component ships agent or IDE configuration that executes a command without a separate step: a Claude Code / Gemini CLI / Cursor hook, or a VS Code task that runs when the folder opens. Opening the project in that tool runs it with the developer's privileges.

"command": ".cursor/hooks/goal-continue.sh",

Fix: Read the command and anything it runs before opening this project in an agent or editor. A published package has no reason to ship project auto-run config.

MEDIUMNode.js filesystem readST-FS-NODE-READ

The component reads files from disk.

const content = fs.readFileSync(authPath, "utf8");
const prj = JSON.parse(fs.readFileSync(prjPath, "utf8"));
const token = JSON.parse(fs.readFileSync(tokenPath, "utf8"));

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMNode.js filesystem write/deleteST-FS-NODE-WRITE

The component writes or deletes files on disk.

fs.writeFileSync(authPath, JSON.stringify(config2, null, 2), { mode: 384 });
fs.writeFileSync(tokenPath, tokenJson);

Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.

Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.

MEDIUMNode.js network egressST-NET-NODE

The component makes outbound network requests.

const response = await fetch(discoveryUrl, {
return await fetch(tokenEndpoint, {
const res = await fetch(url2, {
/** Custom fetch (defaults to global fetch). */

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

LOWDelegated authentication (OAuth 2.0 / OIDC)ST-AUTH-DELEGATED

An OAuth 2.0 / OpenID Connect delegated-authentication flow was detected (authorization-code / refresh-token / token-exchange grant, an OIDC authorize/discovery endpoint or id_token, or a delegation library). Tools authenticate with the end user's delegated, scoped credentials rather than a long-lived embedded service credential. (2 occurrence(s) shown as evidence).

const discoveryUrl = `${VERCEL_ISSUER}/.well-known/openid-configuration`;
grant_type: "refresh_token",

Fix: Delegated auth is a lower-blast-radius execution context than an embedded static credential. Confirm the requested scopes are minimal and that tokens are never logged or forwarded off-host.

LOWMCP tool surface detectedST-MCP-DETECTED

An MCP tool surface (manifest or tool definitions) was found.

server.tool("projects_projection_issue", "Issue one historical ProductProjection receipt. Requires server policy; grants no deployment authority.", { project_id: exports_external.string(), request: ProjectionIssueSchema }, async ({ project_ …
server.tool("projects_projection_get", "Read an exact authorized immutable ProductProjection receipt.", { project_id: exports_external.string(), receipt_id: exports_external.string(), ...ProjectionReadSchema.shape }, async ({ project_id, re …
const server = new McpServer({
server.tool("projects_roots_list", "List registered root folders and path templates for projects. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_roots_add", "Register a root folder that projects can be created under.", {
server.tool("projects_roots_show", "Show one registered root by id or slug.", { id: exports_external.string() }, async (input) => {
server.tool("projects_roots_update", "Update a registered root folder and its defaults.", {
server.tool("projects_roots_delete", "Delete a registered root. Refuses roots referenced by projects unless detach_projects=true.", {
server.tool("projects_roots_match", "Score and match registered roots by path, kind, tags, and GitHub org.", {
server.tool("projects_recipes_list", "List project recipes for agent-visible creation defaults. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_recipes_add", "Register a project recipe with optional default tags and JSON steps.", {
server.tool("projects_recipes_built_ins", "List built-in project recipe definitions. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_recipes_seed_defaults", "Create any missing built-in project recipes.", {}, async () => {
server.tool("projects_agents_list", "List registered agents, or agents assigned to a specific project. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_agents_add", "Register a human, CLI, service, or AI agent for project attribution.", {
server.tool("projects_agents_assign", "Assign a registered agent to a project role and record an audit event.", {
server.tool("projects_tmux_profiles_list", "List saved project tmux profiles. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_tmux_profiles_add", "Create a saved tmux profile with optional windows.", {
server.tool("projects_tmux_profiles_apply", "Apply a saved tmux profile to a project.", {
server.tool("projects_list", "List registered projects across all roots and arbitrary paths. Full records by default; pass compact=true for compact summaries.", {
server.tool("projects_search", "Search registered projects with a compact bounded page by default. Searches discovery fields unless query_scope is explicit; use projects_show for full detail. Legacy projects_list remains unchanged.", {
server.tool("projects_show", "Show a project with locations and event history. Full records by default; pass compact=true for a compact summary.", {
server.tool("projects_render_list", "Return a validated JSON Render spec for the projects list surface.", {
server.tool("projects_render_show", "Return a validated JSON Render spec for one project detail surface.", { id: exports_external.string() }, async (input) => {
server.tool("projects_render_sessions", "Return a validated JSON Render spec for recent project start sessions.", { project: exports_external.string(), limit: exports_external.number().int().positive().max(100).optional(), unrenamed: export …

Why it matters: Just context — review which tools it offers and their permissions.

Fix: Review the declared MCP tools and their permissions.

How attackers abuse these capabilities

Interactive labs on the attack class behind the rules above. They show the technique, not anything found in @hasna/projects.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →