Loading npm security reports…
LPM treats this as warn-only first-party agent extension lifecycle risk. The install hook invokes `skyline setup`, which documentation says configures a Skyline daemon and agent plugins. The wrapper source itself contains no confirmed network, harvesting, or destructive behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg