AI Coding Framework for Claude Code — 7+ agents, 51 skills, multi-LLM orchestration
LPM blocks this version under the AI-agent control-surface policy. Installation silently modifies broad, foreign AI-agent configuration surfaces. It installs agent/skill content and a Codex lifecycle notify program, affecting future sessions.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/infra/lib/TaskContext.jsView on unpkg · L26Package source references a known benign dynamic code generation pattern.
dist/tools/convention/applyQualityRules.jsView on unpkg · L21Package source references dynamic require/import behavior.
dist/infra/lib/MemoryManager.jsView on unpkg · L33Source writes installer persistence such as shell profile or service configuration.
dist/cli/commands/codex-proxy.jsView on unpkg · L33A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/infra/lib/codex-proxy.jsView on unpkg · L912Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/infra/lib/codex-proxy.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli/commands/telegram.jsView on unpkg · L100Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/telegram.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
vibe/setup.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/scripts/llm-orchestrate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/update.jsView on unpkgHardcoded password in skills/vibe.e2e-commerce/templates/test-scenarios.md
skills/vibe.e2e-commerce/templates/test-scenarios.mdView on unpkg · L16Hardcoded password in vibe/rules/quality/testing-strategy.md
vibe/rules/quality/testing-strategy.mdView on unpkg · L121Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L35Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L35Package source invokes a package manager install command at runtime.
dist/cli/commands/telegram.jsView on unpkg · L100Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/telegram.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
vibe/setup.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/scripts/llm-orchestrate.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/update.jsView on unpkgHardcoded password in skills/vibe.e2e-commerce/templates/test-scenarios.md
skills/vibe.e2e-commerce/templates/test-scenarios.mdView on unpkg · L16Hardcoded password in vibe/rules/quality/testing-strategy.md
vibe/rules/quality/testing-strategy.mdView on unpkg · L121Package source references child process execution.
dist/infra/lib/TaskContext.jsView on unpkg · L26Package source references a known benign dynamic code generation pattern.
dist/tools/convention/applyQualityRules.jsView on unpkg · L21Package source references dynamic require/import behavior.
dist/infra/lib/MemoryManager.jsView on unpkg · L33Source writes installer persistence such as shell profile or service configuration.
dist/cli/commands/codex-proxy.jsView on unpkg · L33A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/infra/lib/codex-proxy.jsView on unpkg · L912Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/infra/lib/codex-proxy.jsView on unpkg