AgentLink local agent CLI
LPM treats this as warn-only first-party agent extension lifecycle risk. A globally installed, previously adopted AgentLink runtime can fetch a vendor-hosted package archive during postinstall, stage it, and execute its CLI self-check. At runtime it connects to the AgentLink relay and invokes local Codex/Claude-style CLIs for relay-provided work.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
launcher/launcher.cjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/claude.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L37This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/claude.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/emergency-upgrade.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
launcher/launcher.cjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/service.jsView on unpkg · L1