Agile Spec-Driven-Development Framework for AI agents
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically populates an AI-agent configuration directory in the consumer project. A global install instead writes under the user's home directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs a postinstall script.
package.jsonView on unpkg · L34Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/story-verify/examples/pytest-project/tests/test_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/story-verify/examples/pytest-project/tests/test_auth.pyView on unpkgThe postinstall script installs into .claude without asking the user.
scripts/postinstall.jsView on unpkg · L3The installer targets the consuming project or, for global installs, the user home directory.
scripts/install.jsView on unpkg · L33The installer copies the package's skills and agents into that AI-agent control directory.
scripts/install.jsView on unpkg · L82This report applies to agile-sddf@2.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L35Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L35The manifest automatically runs a postinstall script.
package.jsonView on unpkg · L34Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/story-verify/examples/pytest-project/tests/test_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/story-verify/examples/pytest-project/tests/test_auth.pyView on unpkgThe postinstall script installs into .claude without asking the user.
scripts/postinstall.jsView on unpkg · L3The installer targets the consuming project or, for global installs, the user home directory.
scripts/install.jsView on unpkg · L33The installer copies the package's skills and agents into that AI-agent control directory.
scripts/install.jsView on unpkg · L82