Autonomous quality-assurance methodology — agent skills, harness hooks, return-shape schemas, and post-install plumbing that drive the @civitas-cerebrum/element-interactions framework end-to-end.
LPM flags this version as an AI-agent control-surface risk. Installation mutates the user-wide Claude Code hook and settings control surface. It installs numerous enforcement hooks and a downloaded executable that affect later agent sessions.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
hooks/lib/validator.bundle.mjsView on unpkg · L10271Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L29Package ships non-JavaScript build or shell helper files.
hooks/subagent-schema-preread-gate.shView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L6Package source references a known benign dynamic code generation pattern.
hooks/lib/validator.bundle.mjsView on unpkg · L10271Package ships non-JavaScript build or shell helper files.
hooks/subagent-schema-preread-gate.shView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L29