Devflow 专项研发 Pi,基于固定版本 OMP Runtime 组装研发状态机、代码智能、设计、实现与质量门禁。
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically patches local AI-agent dependency source. No confirmed data theft or remote attack behavior was established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package declares an automatic postinstall hook.
package.jsonView on unpkg · L10Package ships non-JavaScript build or shell helper files.
plugins/devflow-core/runtime/hooks/post_tool.pyView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
plugins/devflow-intel/extensions/devflow-intel.tsView on unpkgThe hook targets source files of its AI-agent dependency.
bin/apply-opencode-go-session-hotfix.mjsView on unpkg · L11The hook replaces dependency code and writes the result during installation.
bin/apply-opencode-go-session-hotfix.mjsView on unpkg · L50This report applies to @guanlin4924/devflow-pi@0.1.91.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13The package declares an automatic postinstall hook.
package.jsonView on unpkg · L10Package ships non-JavaScript build or shell helper files.
plugins/devflow-core/runtime/hooks/post_tool.pyView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
plugins/devflow-intel/extensions/devflow-intel.tsView on unpkgThe hook targets source files of its AI-agent dependency.
bin/apply-opencode-go-session-hotfix.mjsView on unpkg · L11The hook replaces dependency code and writes the result during installation.
bin/apply-opencode-go-session-hotfix.mjsView on unpkg · L50