Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically invokes a native setup action intended to configure agent integrations. No confirmed credential theft, network exfiltration, or destructive behavior is visible in the JavaScript wrapper.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package declares an automatic postinstall script.
package.jsonView on unpkg · L28The postinstall handler launches the resolved native executable with the setup command unless an environment opt-out is set.
npm/postinstall.jsView on unpkg · L62This report applies to @einsia/agent-git@0.2.9.
See version security history for other recorded verdicts.
Evidence last updated: .
The package declares an automatic postinstall script.
package.jsonView on unpkg · L28Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40The postinstall handler launches the resolved native executable with the setup command unless an environment opt-out is set.
npm/postinstall.jsView on unpkg · L62