Inter-assistant communication bus, monotonic fencing locks, and work queues over Redis
LPM flags this version as an AI-agent control-surface risk. The automatic installer mutates several existing AI-agent control surfaces in the user's home directory. It also installs a plugin capable of interrupting an active OpenCode session.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs its installer automatically after npm installation.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L35This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/ci/build.shView on unpkgThis report applies to @axiomantic/rhizo@0.1.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L19The package runs its installer automatically after npm installation.
package.jsonView on unpkg · L19Package ships non-JavaScript build or shell helper files.
scripts/ci/build.shView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L35This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkg