Build, test, and deploy BDK bots and agents as code on Cursor's agent harness.
LPM treats this as warn-only first-party agent extension lifecycle risk. Package installation automatically copies package-owned skills into the user's Cursor skills directory. Slack continuation handling can also write a carrier script and register Cursor hooks in the agent workspace.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L194A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgThis report applies to @cursor/july@0.2.22.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L381Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L381A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L194