Sub-Second APFS Copy-on-Write Workspaces & Zero-Mirage Git Weaving Engine
LPM flags this version as an AI-agent control-surface risk. An automatic installation hook modifies configuration for multiple AI coding assistants when their base directories exist. This is an unconsented cross-application control-surface write.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers scripts/postinstall.js as an automatic npm post-install hook.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgThe post-install script creates destination directories and writes a file without a consent prompt.
scripts/postinstall.jsView on unpkg · L192This report applies to @axiomantic/braid@0.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers scripts/postinstall.js as an automatic npm post-install hook.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgThe post-install script creates destination directories and writes a file without a consent prompt.
scripts/postinstall.jsView on unpkg · L192