Local AI work system engine and multi-project dashboard
LPM flags this version as an AI-agent control-surface risk. Installing the package mutates AI-agent instruction and skill files across previously registered projects. It also starts or restarts a background engine during installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/runtime.mjsView on unpkg · L1Package source references child process execution.
dist/install/runtime.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install/runtime.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/install/runtime.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/install/runtime.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install/runtime.mjsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.mjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/dashboard/project-worker.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dashboard/project-worker.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/agent-baseline/skills/personal-dashboard/scripts/validate_dashboard.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agents/auto-capture.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/service/daemon-entry.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L26Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli/index.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/agent-baseline/skills/personal-dashboard/scripts/validate_dashboard.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agents/auto-capture.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/service/daemon-entry.mjsView on unpkgPackage source references child process execution.
dist/install/runtime.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install/runtime.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/install/runtime.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/install/runtime.mjsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/runtime.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install/runtime.mjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/dashboard/project-worker.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dashboard/project-worker.mjsView on unpkg