Loading npm security reports…
Safe per-process Natural Conversation Mode for Pi, with /talk commands and read-only tool constraints.
LPM treats this as warn-only first-party agent extension lifecycle risk. A Pi extension can alter its host conversation tool policy and, after explicit setup, capture microphone audio and invoke configured STT/TTS providers. No unconsented install-time behavior or concrete malicious chain was found.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/providers/tts-piper.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/providers/tts-piper.mjsView on unpkg