AI development process auto-documentation tool - generates structured commit summaries from Claude Code, Codex, Gemini, OpenCode, Cursor, and Copilot sessions
LPM treats this as warn-only first-party agent extension lifecycle risk. A guarded upgrade-time installer can re-enable Jolli hooks and MCP registrations across detected AI-agent surfaces. No credential theft, destructive action, or remote code-loading chain was confirmed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/graph-assets/vendor/elk.bundled.jsView on unpkg · L6611Package source references weak cryptographic algorithms.
dist/QueueWorker.jsView on unpkg · L49Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Package source references dynamic require/import behavior.
dist/graph-assets/vendor/elk.bundled.jsView on unpkg · L6611Package source references weak cryptographic algorithms.
dist/QueueWorker.jsView on unpkg · L49