Terminal-native GoodVibes client for coding, operations, knowledge and channel workflows — a pure client of the GoodVibes daemon.
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall installs GoodVibes-owned agent and skill markdown into the user’s GoodVibes directory. The bundled instructions can influence a GoodVibes agent’s workflow when loaded.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
src/runtime/onboarding/apply.tsView on unpkg · L90Package source references child process execution.
bin/launcher-support.jsView on unpkg · L3Package source references dynamic require/import behavior.
src/input/commands/hooks-runtime.tsView on unpkg · L120Source writes persistence or remote-access backdoor material.
src/runtime/sandbox-public-gaps.tsView on unpkg · L2Source writes installer persistence such as shell profile or service configuration.
src/runtime/sandbox-public-gaps.tsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/verification/live-verifier.tsView on unpkg · L89Package ships non-JavaScript build or shell helper files.
scripts/check-bun.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/input/commands/platform-sandbox-qemu.tsView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L44Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L44Package ships non-JavaScript build or shell helper files.
scripts/check-bun.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/input/commands/platform-sandbox-qemu.tsView on unpkgPackage contains a possible secret pattern.
src/runtime/onboarding/apply.tsView on unpkg · L90Package source references child process execution.
bin/launcher-support.jsView on unpkg · L3Package source references dynamic require/import behavior.
src/input/commands/hooks-runtime.tsView on unpkg · L120Source writes installer persistence such as shell profile or service configuration.
Source writes persistence or remote-access backdoor material.
src/runtime/sandbox-public-gaps.tsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/verification/live-verifier.tsView on unpkg · L89