Agent observability and knowledge capture layer for AI coding tools.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can automatically add this package's onboarding skills when existing Claude or Codex directories are detected. No install-time network or secret-exfiltration behavior was confirmed in the inspected setup path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/setup-agent-skills.mjsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
.output/cli.jsView on unpkg · L65Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
.output/cli.jsView on unpkg · L63This report applies to @tonyclaw/agent-inspector@4.0.32.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
.output/cli.jsView on unpkg · L63Source file is highly similar to a previously finalized malicious package; route for source-aware review.
.output/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
.output/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L108Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L108A single source file combines environment access, network access, and code or shell execution; review context before blocking.
.output/cli.jsView on unpkg · L65Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
.output/cli.jsView on unpkg · L63Package source references child process execution.
scripts/setup-agent-skills.mjsView on unpkg · L3A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
.output/cli.jsView on unpkg · L63Source file is highly similar to a previously finalized malicious package; route for source-aware review.
.output/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
.output/cli.jsView on unpkg