Qianfan command-line client
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm installation downloads and executes an external binary. That binary is automatically asked to add skills to detected local AI-agent directories.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook automatically downloads a platform binary.
package.jsonView on unpkg · L18Package source references child process execution.
scripts/postinstall.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L20Package source invokes a package manager install command at runtime.
scripts/run.jsView on unpkg · L28This report applies to @mingliuyiming/qianfan-cli-test@0.0.1-test.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L19Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L19The postinstall hook automatically downloads a platform binary.
package.jsonView on unpkg · L18Package source references child process execution.
scripts/postinstall.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.jsView on unpkg · L20Package source invokes a package manager install command at runtime.
scripts/run.jsView on unpkg · L28