Loading npm security reports…
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation triggers the package's `setup` subcommand through a platform binary. Documentation describes a Skyline daemon autostart and best-effort Skyline agent-plugin installation; binary internals are not included.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg