Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically invokes the package's own setup command, which the package describes as configuring agent integrations. This is a guarded first-party agent setup lifecycle risk; no malicious effect was established from inspected source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe manifest runs a postinstall script during installation.
package.jsonView on unpkg · L39The postinstall script invokes the installed CLI's setup command unless AGIT_SKIP_SETUP is truthy.
npm/postinstall.jsView on unpkg · L72This report applies to @einsia/agent-git@0.2.22.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40The manifest runs a postinstall script during installation.
package.jsonView on unpkg · L39The postinstall script invokes the installed CLI's setup command unless AGIT_SKIP_SETUP is truthy.
npm/postinstall.jsView on unpkg · L72