Loading npm security reports…
Skill-first workflow suite for agentic coding assistants
LPM flags this version as an AI-agent control-surface risk. The package has a real agent-control-surface mutation risk because npm postinstall installs skills and workflow hooks into local Codex/Claude locations. Inspection did not find payload execution, credential theft, or exfiltration, and the behavior is aligned with the package's stated purpose.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/install-discovery.mjsView on unpkg · L93Package ships non-JavaScript build or shell helper files.
skills/debug/find-polluter.shView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L75Package ships non-JavaScript build or shell helper files.
skills/debug/find-polluter.shView on unpkgPackage source references weak cryptographic algorithms.
src/install-discovery.mjsView on unpkg · L93