Broken publish (unresolved workspace dependency). Use 0.5.1+.
Run your own agents as E2EE NoPeek bots. Pairs with a one-time code, runs every bot you own, and pipes messages to any command or webhook.
LPM treats this as warn-only first-party agent extension lifecycle risk. The package is an intentional local agent bridge with command and webhook backends. It can persist a first-party background service, but only when the user explicitly runs its install command; no install-time execution is present.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/backends.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/backends.jsView on unpkg · L8Package source invokes a package manager install command at runtime.
dist/service.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L4Package source references weak cryptographic algorithms.
dist/backends.jsView on unpkg · L8This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/backends.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/service.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
dist/service.jsView on unpkg · L4