Hum (हम): a self-improving coding agent for your terminal.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the npm package automatically starts an engine bootstrapper. It can fetch and execute a remote uv installer and create a Python engine under ~/.hum.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L8Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L317A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L75762Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L57423Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L317A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L75762Package source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L8Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L57423