One CLI for all your AI coding agents - versions, config, cloud dispatch, sessions, and teams (now with first-class Grok Build CLI support)
LPM treats this as warn-only first-party agent extension lifecycle risk. The package's postinstall performs first-party CLI setup and, on macOS, installs a bundled helper and may restart its own daemon. Separate runtime commands can query AI-provider usage APIs using local credentials.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/commands/secrets.jsView on unpkg · L173Package source references shell execution.
dist/lib/monitors/sources/command.jsView on unpkg · L5Package source references dynamic require/import behavior.
dist/lib/sqlite.jsView on unpkg · L15Package source references weak cryptographic algorithms.
dist/lib/platform/ipc.jsView on unpkg · L12Source writes installer persistence such as shell profile or service configuration.
dist/lib/agents.jsView on unpkg · L11A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lib/auto-dispatch-linear.jsView on unpkg · L13Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lib/auto-dispatch-linear.jsView on unpkg · L13Source appears to send environment or credential material to an external endpoint.
dist/lib/usage.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/lib/daemon.jsView on unpkg · L13A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/lib/menubar/install-menubar.jsView on unpkg · L17Package ships high-entropy non-source blobs.
dist/lib/menubar/MenubarHelper.app/Contents/Resources/AppIcon.icnsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Package source references shell execution.
dist/lib/monitors/sources/command.jsView on unpkg · L5A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lib/auto-dispatch-linear.jsView on unpkg · L13Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lib/auto-dispatch-linear.jsView on unpkg · L13Source appears to send environment or credential material to an external endpoint.
dist/lib/usage.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/lib/daemon.jsView on unpkg · L13A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/lib/menubar/install-menubar.jsView on unpkg · L17Package ships high-entropy non-source blobs.
dist/lib/menubar/MenubarHelper.app/Contents/Resources/AppIcon.icnsView on unpkgPackage contains a possible secret pattern.
dist/commands/secrets.jsView on unpkg · L173Package source references dynamic require/import behavior.
dist/lib/sqlite.jsView on unpkg · L15Package source references weak cryptographic algorithms.
dist/lib/platform/ipc.jsView on unpkg · L12Source writes installer persistence such as shell profile or service configuration.
dist/lib/agents.jsView on unpkg · L11