Command line interface for Tigris object storage
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can add a bundled Tigris skill to an existing Claude Code configuration. This is an unprompted but narrow same-vendor agent-extension installation; no credential theft, remote payload, or destructive install-time action was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/chunk-PNRZDYCK.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
postinstall.cjsView on unpkg · L1The postinstall hook copies a Tigris skill into an existing Claude Code directory without an explicit user command.
postinstall.cjsView on unpkg · L12Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L68Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L68Package source references dynamic require/import behavior.
dist/chunk-PNRZDYCK.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
postinstall.cjsView on unpkg · L1The postinstall hook copies a Tigris skill into an existing Claude Code directory without an explicit user command.
postinstall.cjsView on unpkg · L12