Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically launches a setup action supplied by a platform-specific binary. This can configure agent-facing integrations, but the binary implementation is unavailable here, so no confirmed malicious action is established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package declares an automatic postinstall hook.
package.jsonView on unpkg · L28The postinstall script invokes the bundled command's setup action unless an environment opt-out is set.
npm/postinstall.jsView on unpkg · L62This report applies to @einsia/agent-git@0.2.10.
See version security history for other recorded verdicts.
Evidence last updated: .
The package declares an automatic postinstall hook.
package.jsonView on unpkg · L28Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40The postinstall script invokes the bundled command's setup action unless an environment opt-out is set.
npm/postinstall.jsView on unpkg · L62