Astra OS — a portable agent harness that drives one coding agent (Pi SDK or claude, droid, opencode, hermes, codex) through five front-loaded software-factory gates: product intent, architecture with adversarial audit, program design contracts, DAG planni
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can add Astra-owned skills, commands, and a local stdio MCP registration to detected AI-agent environments. This is an automatic extension setup, not a confirmed remote-control or exfiltration chain.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/astra.mjs#virtual:normalized:round1View on unpkg · L458Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/astra.mjsView on unpkg · L51Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L20Package source references dynamic require/import behavior.
bin/astra.mjs#virtual:normalized:round1View on unpkg · L458Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/astra.mjsView on unpkg · L51