Cascade organizational intelligence for Claude Code. Skills, MCP server, and setup tools.
LPM treats this as warn-only first-party agent extension lifecycle risk. Explicit `cascade-kit setup` installs Cascade commands and registers MCP servers in Claude settings and the current project's .mcp.json. This creates an agent-extension control surface, including two third-party npx MCP entries.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/setup.mjsView on unpkg · L21Package source invokes a package manager install command at runtime.
bin/setup.mjsView on unpkg · L6Package source references dynamic require/import behavior.
bin/setup.mjsView on unpkg · L26Supabase service role key (JWT) in mcp-server/index.js
mcp-server/index.jsView on unpkg · L43090Package ships non-JavaScript build or shell helper files.
data/ingest/youtube_transcript.pyView on unpkgGoogle API key in mcp-server/tools/ingest-curator-item.js
mcp-server/tools/ingest-curator-item.jsView on unpkg · L341Package source references a known benign dynamic code generation pattern.
mcp-server/index.jsView on unpkg · L2946Package source invokes a package manager install command at runtime.
bin/setup.mjsView on unpkg · L6Package source references dynamic require/import behavior.
bin/setup.mjsView on unpkg · L26Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/setup.mjsView on unpkg · L21Supabase service role key (JWT) in mcp-server/index.js
mcp-server/index.jsView on unpkg · L43090Package ships non-JavaScript build or shell helper files.
data/ingest/youtube_transcript.pyView on unpkgPackage source references a known benign dynamic code generation pattern.
mcp-server/index.jsView on unpkg · L2946Google API key in mcp-server/tools/ingest-curator-item.js
mcp-server/tools/ingest-curator-item.jsView on unpkg · L341