Multi-Agent Swarm Orchestration, Empirical Dialectics & Ceremonies on top of Rhizo & Vine
LPM flags this version as an AI-agent control-surface risk. An automatic installation hook modifies configuration for independently installed AI coding assistants. It also retrieves and installs an opaque native executable during installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs the installation script after package installation.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1The installation script removes an existing assistant rule file and writes its own rule file into detected Claude Code and OpenCode configuration directories.
scripts/postinstall.jsView on unpkg · L115Package ships non-JavaScript build or shell helper files.
scripts/launch_tmux_swarm.shView on unpkgThis report applies to @axiomantic/garden@0.1.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L19The manifest automatically runs the installation script after package installation.
package.jsonView on unpkg · L19Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
scripts/launch_tmux_swarm.shView on unpkgThe installation script removes an existing assistant rule file and writes its own rule file into detected Claude Code and OpenCode configuration directories.
scripts/postinstall.jsView on unpkg · L115