Terminal-native GoodVibes client for coding, operations, knowledge and channel workflows — a pure client of the GoodVibes daemon.
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall fetches a platform binary and deploys GoodVibes-owned agent extensions. This is an unprompted package-owned agent-extension lifecycle action, not a confirmed foreign control-surface takeover.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
src/runtime/onboarding/apply.tsView on unpkg · L90This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-support.jsView on unpkgPackage source references child process execution.
bin/launcher-support.jsView on unpkg · L3Package source references dynamic require/import behavior.
src/input/commands/hooks-runtime.tsView on unpkg · L120A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/verification/live-verifier.tsView on unpkg · L89Source writes persistence or remote-access backdoor material.
src/runtime/sandbox-public-gaps.tsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
scripts/check-bun.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/input/commands/platform-sandbox-qemu.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L44Package ships non-JavaScript build or shell helper files.
scripts/check-bun.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/input/commands/platform-sandbox-qemu.tsView on unpkgPackage contains a possible secret pattern.
src/runtime/onboarding/apply.tsView on unpkg · L90Package source references child process execution.
bin/launcher-support.jsView on unpkg · L3This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-support.jsView on unpkgPackage source references dynamic require/import behavior.
src/input/commands/hooks-runtime.tsView on unpkg · L120A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/verification/live-verifier.tsView on unpkg · L89Source writes persistence or remote-access backdoor material.