MCP security scanner and CI gate. Test, secure, and monitor MCP servers with attack simulation, schema drift detection, health scoring, and SARIF before agents depend on them.
LPM treats this as warn-only first-party agent extension lifecycle risk. A guarded postinstall can add a scheduled GitHub Actions workflow to an MCP project. It is opt-in through project configuration or an environment variable, so no unconsented install-time mutation is confirmed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/src/ci-issue.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/src/commands/test.jsView on unpkg · L242Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/skill-scan.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/helpers.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/risk-graph.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/attack-sim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/runtime-profile.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L100Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L100Package source references child process execution.
dist/src/ci-issue.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/skill-scan.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/commands/helpers.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/risk-graph.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/attack-sim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/checks/runtime-profile.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/src/commands/test.jsView on unpkg · L242