CLI tool for Bohrium scientific computing platform
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall retrieves companion binaries, verifies their SHA-256 values supplied by the same remote source, and installs them in package-owned ~/.bohr tool directories. No confirmed credential theft or foreign AI-agent control-surface modification was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall automatically downloads two external CLI binaries.
postinstall.jsView on unpkg · L3A postinstall environment variable can redirect the trisol manifest/download server.
postinstall.jsView on unpkg · L19Package source invokes a package manager install command at runtime.
run.jsView on unpkg · L64Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9postinstall automatically downloads two external CLI binaries.
postinstall.jsView on unpkg · L3A postinstall environment variable can redirect the trisol manifest/download server.
postinstall.jsView on unpkg · L19Package source invokes a package manager install command at runtime.
run.jsView on unpkg · L64