SDLC 最小集 CLI(sdlc-cli)— 本地即真源的中间产物仓库与工作区装配
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package automatically writes configuration and bundled skills into global AI-agent skill directories. A separate session feature can upload supplied transcript files to a default remote endpoint, but this package does not install the hooks that invoke it.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/cli.jsView on unpkg · L632Package ships non-JavaScript build or shell helper files.
skills/importing-artifacts/scripts/scan_source.pyView on unpkgThis report applies to @g7e6-sdlc/sdlc-cli@1.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18Package ships non-JavaScript build or shell helper files.
skills/importing-artifacts/scripts/scan_source.pyView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/cli.jsView on unpkg · L632