Performance and assurance harness for AI coding agents with repository intelligence, native architecture pulse, governed memory, security gates, and verifiable delivery.
LPM flags this version as an AI-agent control-surface risk. Install-time code imports a governed kit into the consumer project and writes AI-agent configuration. This mutates shared and third-party agent control surfaces without an explicit user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/src/cli.mjsView on unpkg · L589Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/templates.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/memory-contract.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/memory-lifecycle.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/proof-replay.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L92Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L92Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/templates.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
assets/enterprise-ai-agent-os/.cursor/skills/design-scalable-systems/scripts/capacity_cost_model.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/memory-contract.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/memory-lifecycle.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/proof-replay.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/src/cli.mjsView on unpkg · L589