Agent skills and rules for ITCase projects
LPM flags this version as an AI-agent control-surface risk. Installation automatically replaces the consumer project's Cursor rules and skills. Existing agent instructions are recursively removed without consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs scripts/postinstall.js after installation.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe installer selects the consumer project using INIT_CWD or the working directory.
scripts/postinstall.jsView on unpkg · L20It targets the consumer project's .cursor/rules and .cursor/skills directories.
scripts/postinstall.jsView on unpkg · L130Synchronization recursively deletes existing destination directories before copying package content.
scripts/postinstall.jsView on unpkg · L119This report applies to @itcase/agent-skills@1.0.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Top-level execution installs rules and skills without a consent prompt or saved preference check.
scripts/postinstall.jsView on unpkg · L169Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10package.json automatically runs scripts/postinstall.js after installation.
package.jsonView on unpkg · L10The installer selects the consumer project using INIT_CWD or the working directory.
scripts/postinstall.jsView on unpkg · L20Synchronization recursively deletes existing destination directories before copying package content.
scripts/postinstall.jsView on unpkg · L119It targets the consumer project's .cursor/rules and .cursor/skills directories.
scripts/postinstall.jsView on unpkg · L130Top-level execution installs rules and skills without a consent prompt or saved preference check.
scripts/postinstall.jsView on unpkg · L169