Structured multi-agent development workflow for AI coding agents — scrum board, role-bounded scrum master / developer / tester agents, and 30+ slash-command skills. Works with Claude Code, GitHub Copilot, and Codex.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies AI-agent discovery and instruction files in the consuming project. It injects packaged skills and agents without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs on package installation.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L6Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
hooks/on_session_end.shView on unpkgThis report applies to @jenga-ai/agent@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16An automatic postinstall hook runs on package installation.
package.jsonView on unpkg · L15Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
hooks/on_session_end.shView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.jsView on unpkg