Global Codex skill plus TUI/GUI control room and token-aware orchestration CLI for Codex subagents.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically places a bundled skill in the user's global Codex configuration. This alters future AI-agent behavior outside the consuming project.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
tools/install-codex-skill.mjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
tools/install-codex-skill.mjsView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/workflow_v2_validation.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/aow.mjs#virtual:normalized:round1View on unpkgThis report applies to agent-orchestration-workflow@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
tools/install-codex-skill.mjsView on unpkg · L1Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/workflow_v2_validation.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/aow.mjs#virtual:normalized:round1View on unpkgRuntime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
tools/install-codex-skill.mjsView on unpkg