Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM flags this version as an AI-agent control-surface risk. Installation automatically runs an external platform binary to configure AI-agent integration surfaces. No user command or affirmative setup choice is required.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers a postinstall lifecycle hook.
package.jsonView on unpkg · L39Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
npm/postinstall.jsView on unpkgThe hook automatically invokes a resolved platform binary with the setup command unless an environment opt-out is already set.
npm/postinstall.jsView on unpkg · L62The setup is described as installing skills, hooks, MCP wiring, and an AGENTS file during installation.
npm/postinstall.jsView on unpkg · L7This report applies to @einsia/agent-git@0.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40The package registers a postinstall lifecycle hook.
package.jsonView on unpkg · L39The setup is described as installing skills, hooks, MCP wiring, and an AGENTS file during installation.
npm/postinstall.jsView on unpkg · L7The hook automatically invokes a resolved platform binary with the setup command unless an environment opt-out is already set.
npm/postinstall.jsView on unpkg · L62This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
npm/postinstall.jsView on unpkg