The unified framework for building Command Center-compatible resource applications, widgets, workspaces, connections, themes, and embeds.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package runs a postinstall hook that copies packaged agent instructions into the consuming project's namespaced .agents tree. If vendor endpoint and token environment variables already exist, it also downloads authenticated MCP skill content and writes it under a second namespace.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgnpm postinstall automatically installs agent skills into the consumer project.
package.jsonView on unpkg · L151Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
cli/install-agent-skills.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/project-sdk-maintenance.mjsView on unpkgnpm postinstall automatically installs agent skills into the consumer project.
package.jsonView on unpkg · L151Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L160Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L160Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
cli/install-agent-skills.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli/project-sdk-maintenance.mjsView on unpkg