AI tool security proxy: protect any AI tool server with customizable policies, path/command constraints, rate limiting, and audit logging. No code changes required.
LPM treats this as warn-only first-party agent extension lifecycle risk. An explicit global setup installs persistent agent hooks and an OpenCode plugin. Those hooks send redacted conversation and audit data to SolonGate when configured with its API key.
Package source references child process execution.
dist/tui/index.jsView on unpkg · L143Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/tui/index.jsView on unpkg · L13Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/tui/index.jsView on unpkg · L13Source writes installer persistence such as shell profile or service configuration.
dist/tui/index.jsView on unpkg · L13Package source references dynamic require/import behavior.
dist/cli-launch.jsView on unpkg · L37A single source file combines environment access, network access, and code or shell execution; review context before blocking.
hooks/shield.mjsView on unpkg · L286Source file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/shield.mjsView on unpkgSource appears to send environment or credential material to an external endpoint.
hooks/guard.mjsView on unpkg · L13Source reaches cloud instance metadata or link-local credential endpoints.
hooks/guard.mjsView on unpkg · L13Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L43Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
hooks/guard.bundled.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/guard.bundled.mjsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lib.jsView on unpkg · L42A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
dist/lib.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/tui/index.jsView on unpkg · L13Source writes installer persistence such as shell profile or service configuration.
dist/tui/index.jsView on unpkg · L13Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/tui/index.jsView on unpkg · L13Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L43Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
hooks/guard.bundled.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/guard.bundled.mjsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lib.jsView on unpkg · L42A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
dist/lib.jsView on unpkgPackage source references child process execution.
dist/tui/index.jsView on unpkg · L143Package source references dynamic require/import behavior.
dist/cli-launch.jsView on unpkg · L37A single source file combines environment access, network access, and code or shell execution; review context before blocking.
hooks/shield.mjsView on unpkg · L286Source file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/shield.mjsView on unpkgSource appears to send environment or credential material to an external endpoint.
hooks/guard.mjsView on unpkg · L13Source reaches cloud instance metadata or link-local credential endpoints.
hooks/guard.mjsView on unpkg · L13A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.jsView on unpkg