Loading npm security reports…
LPM treats this as warn-only first-party agent extension lifecycle risk. Install-time execution automatically runs `skyline setup` through a package-aligned platform binary. The binary payload is not included here, so its setup-side effects cannot be established by source inspection.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg