Elyntic self-improvement lab
LPM treats this as warn-only first-party agent extension lifecycle risk. A Pi session can initiate a release check and, when the package marks it safe, update the globally installed Pi package and run its package synchronizer. The runtime daemon also contains credential-backed messaging actions, although replies and forwards are draft-only by default.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/elyntic-ollama-models.cjsView on unpkg · L23Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/elyntic-ollama-models.cjsView on unpkg · L60A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/elyntic-ollama-models.cjsView on unpkg · L60Package source references a known benign dynamic code generation pattern.
lib/graph/erd/parse-erd.jsView on unpkg · L244Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/design-elevation/index.tsView on unpkg · L21A single source file combines environment access, network access, and code or shell execution; review context before blocking.
daemon/lib/headroom-proxy-manager.jsView on unpkg · L29Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L715A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
backfill-dashboard.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/mental-model/metadata-recompute.tsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
daemon/daemon-manager.jsView on unpkg · L21Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
daemon/elyntic-company-daemon.jsView on unpkgThis report applies to @cgh567/agent@2.6.40.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L13Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L715A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
backfill-dashboard.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/mental-model/metadata-recompute.tsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
daemon/daemon-manager.jsView on unpkg · L21Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
daemon/elyntic-company-daemon.jsView on unpkgPackage source references child process execution.
bin/elyntic-ollama-models.cjsView on unpkg · L23Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/elyntic-ollama-models.cjsView on unpkg · L60A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/elyntic-ollama-models.cjsView on unpkg · L60Package source references a known benign dynamic code generation pattern.
lib/graph/erd/parse-erd.jsView on unpkg · L244Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/design-elevation/index.tsView on unpkg · L21A single source file combines environment access, network access, and code or shell execution; review context before blocking.
daemon/lib/headroom-proxy-manager.jsView on unpkg · L29