Remote worker agent for Yeaft Web Code Agent — connects the native Yeaft engine, CLI providers, and workbench tools
LPM treats this as warn-only first-party agent extension lifecycle risk. Starting the agent implicitly installs and enables a Yeaft Claude plugin in the user-level Claude control surface. This is runtime behavior rather than an npm lifecycle hook, but it fetches mutable remote content and modifies plugin activation state.
Package source references child process execution.
windows-upgrade-runner.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
connection/upgrade.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
local-runtime/web/jszip.min.jsView on unpkg · L12Package source references dynamic require/import behavior.
local-runtime/web/docx-preview.min.jsView on unpkg · L1Package source executes code through a VM context API.
yeaft/tools/js-repl.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
local-run.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
service/macos.jsView on unpkg · L3Package ships high-entropy non-source blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgPackage ships compressed or archive-like blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
local-runtime/web/mermaid.min.jsView on unpkgPackage source references child process execution.
windows-upgrade-runner.jsView on unpkg · L1Package source executes code through a VM context API.
yeaft/tools/js-repl.jsView on unpkg · L1Package ships high-entropy non-source blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgPackage ships compressed or archive-like blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
local-runtime/web/mermaid.min.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
connection/upgrade.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
local-runtime/web/jszip.min.jsView on unpkg · L12Package source references dynamic require/import behavior.
local-runtime/web/docx-preview.min.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
local-run.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
service/macos.jsView on unpkg · L3