Performance and assurance harness for AI coding agents with repository intelligence, portable skills, governed memory, specialist coordination, security gates, and verifiable delivery.
LPM flags this version as an AI-agent control-surface risk. npm postinstall automatically bootstraps a governed AI-agent kit into the consuming repository. It writes managed agent configuration and copies skills into multiple agent control surfaces.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/src/cli.mjsView on unpkg · L1Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/templates.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/change-passport.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L84Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L84Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/templates.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/change-passport.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/src/cli.mjsView on unpkg · L1