Manage agentic work across repositories with durable workbases
LPM flags this version as an AI-agent control-surface risk. Installing the package writes a persistent global Pi agent extension. The extension automatically adds repository-controlled instructions to Pi agent prompts.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
src/utils/interactive-loader.tsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
fixtures/protocol/error.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi-extensions/agency.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/TaskService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/VersionControlService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/chooser.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/process.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/services/ReviewService.tsView on unpkgThis report applies to @markjaquith/agency@3.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L71Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L71A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
fixtures/protocol/error.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi-extensions/agency.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/TaskService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/VersionControlService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/chooser.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/process.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/services/ReviewService.tsView on unpkgPackage source references dynamic require/import behavior.
src/utils/interactive-loader.tsView on unpkg · L3