Build, test, and deploy BDK bots and agents as code on Cursor's agent harness.
LPM treats this as warn-only first-party agent extension lifecycle risk. The package performs guarded agent integration setup: its npm postinstall copies its own skills into the user’s Cursor skills directory, and Slack session setup can add a package-owned hook to a harness workspace.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L185A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgThis report applies to @cursor/july@0.2.14.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
package.jsonView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L185A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37