Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically invokes agent integration setup through an external platform binary. This establishes lifecycle risk, but the inspected source does not establish a malicious attack or broad foreign control-surface mutation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpackage.json automatically runs npm/postinstall.js after installation.
package.jsonView on unpkg · L39The install hook invokes native binary setup unless AGIT_SKIP_SETUP is enabled.
npm/postinstall.jsView on unpkg · L72Global installation invokes package daemon reconciliation; the runtime worker verifies a global installation before reconciliation.
npm/postinstall.jsView on unpkg · L56The binary is resolved from a platform package; its implementation is absent from this snapshot.
npm/lib/resolve.jsView on unpkg · L32This report applies to @einsia/agent-git@0.2.17.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40package.json automatically runs npm/postinstall.js after installation.
package.jsonView on unpkg · L39Global installation invokes package daemon reconciliation; the runtime worker verifies a global installation before reconciliation.
npm/postinstall.jsView on unpkg · L56The install hook invokes native binary setup unless AGIT_SKIP_SETUP is enabled.
npm/postinstall.jsView on unpkg · L72The binary is resolved from a platform package; its implementation is absent from this snapshot.
npm/lib/resolve.jsView on unpkg · L32