Provider-agnostic AI coding agent for your terminal (binary distribution)
LPM treats this as warn-only first-party agent extension lifecycle risk. npm installation fetches and executes an unpinned release binary, then asks it to install default skills. This creates a supply-chain and package-owned agent-extension risk, but the inspected wrapper does not itself show secret theft or destructive behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstallation automatically runs a postinstall bootstrapper.
package.jsonView on unpkg · L8The bootstrapper downloads the latest release artifact with redirects and no integrity verification.
install.jsView on unpkg · L23It clears macOS quarantine from the downloaded executable.
install.jsView on unpkg · L39It automatically executes that opaque executable to install skills into the package-owned agent directory.
install.jsView on unpkg · L47This report applies to @hipmmai/hipmmcode@1.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Installation automatically runs a postinstall bootstrapper.
package.jsonView on unpkg · L8The bootstrapper downloads the latest release artifact with redirects and no integrity verification.
install.jsView on unpkg · L23It clears macOS quarantine from the downloaded executable.
install.jsView on unpkg · L39It automatically executes that opaque executable to install skills into the package-owned agent directory.
install.jsView on unpkg · L47