LPM treats this as warn-only first-party agent extension lifecycle risk. The explicit interactive installer configures selected AI/MCP clients to launch this package via npx and injects a LetRetro API key. The normal server proxies MCP requests to LetRetro.
Static reason
No blocking static signals were detected.
Trigger
User runs `letretro-mcp install` and selects detected clients; runtime starts through configured MCP client.
Impact
Selected AI clients gain a LetRetro MCP server; its remote tool behavior is controlled by the hosted endpoint.
Mechanism
Interactive MCP extension configuration and authenticated stdio-to-HTTPS proxy
Rationale
This is a first-party, user-invoked AI-agent extension setup with remote MCP capability, not concrete malicious behavior. Policy calls for a warning rather than a block.
Evidence
package.jsondist/index.jsdist/install-EXOMYTGT.jsdist/server-KCDLJRZG.jsREADME.md~/.codex/config.toml~/.cursor/mcp.json~/.vscode/mcp.json