Build, test, and deploy BDK bots and agents as code on Cursor's agent harness.
LPM treats this as warn-only first-party agent extension lifecycle risk. Runtime Slack session setup can create a workspace Cursor hook and carrier script to deliver queued Slack follow-ups at tool boundaries. This is a guarded, first-party agent integration capability; no confirmed attack surface was established.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L194A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgThis report applies to @cursor/july@0.2.21.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L376Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L376Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/channels/slack/slack-channel.jsView on unpkg · L194A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels.jsView on unpkgPackage source references dynamic require/import behavior.
dist/internal/authored-loaders.jsView on unpkg · L37