Agent-first CLI for Customer.io APIs
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically invokes a Customer.io CLI subcommand that installs an agent skill. This can alter project or global agent-skill directories, but the inspected wrapper shows no exfiltration or destructive action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs a post-install hook automatically.
package.jsonView on unpkg · L8The hook launches the platform CLI to install an agent skill into the project or global scope without an interactive command.
.npm/postinstall.jsView on unpkg · L46The included documentation identifies the affected Claude and open-agent skill directories.
README.mdView on unpkg · L45Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9The package runs a post-install hook automatically.
package.jsonView on unpkg · L8The hook launches the platform CLI to install an agent skill into the project or global scope without an interactive command.
.npm/postinstall.jsView on unpkg · L46The included documentation identifies the affected Claude and open-agent skill directories.
README.mdView on unpkg · L45