Sub-Second APFS Copy-on-Write Workspaces & Zero-Mirage Git Weaving Engine
LPM flags this version as an AI-agent control-surface risk. The npm post-install hook changes user-level AI coding-assistant rule directories without an explicit user command. It also downloads a native archive through a shell command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs an installer after npm installation.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkgThis report applies to @axiomantic/vine@0.1.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L19The package automatically runs an installer after npm installation.
package.jsonView on unpkg · L18Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkg