Build, test, and deploy BDK bots and agents as code on Cursor's agent harness.
LPM treats this as warn-only first-party agent extension lifecycle risk. Package installation can update Cursor skills without an interactive prompt, and local Slack sessions can add workspace hooks. These are package-owned agent integrations; the inspected code does not establish a concrete attack.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L185A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgThis report applies to @cursor/july@0.2.13.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L284Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L284Source file is highly similar to a previously finalized malicious package; route for source-aware review.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L185