Claude Code audit agents for Appfire apps — ux-auditor (/ux-audit), ui-auditor (/ui-audit), a11y-auditor (/a11y-audit: WCAG 2.2 + axe-core scan feeding the Appfire VPAT/ACR process), /full-audit parallel orchestration. Confluence-ready MD+HTML+PNG output,
LPM treats this as warn-only first-party agent extension lifecycle risk. The package performs install-time Claude Code extension setup by copying its own audit agents and slash commands into .claude. This is a real agent lifecycle risk, but inspection found no confirmed exfiltration, destructive action, or remote code payload.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time source drops package-supplied AI-agent/MCP control files or instructions.
bin/install.jsView on unpkg · L4Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Install-time source drops package-supplied AI-agent/MCP control files or instructions.
bin/install.jsView on unpkg · L4