Claude Code always-on infrastructure — a phone number, a memory, and an alarm clock
LPM treats this as warn-only first-party agent extension lifecycle risk. A global install can automatically retarget and restart an existing Beecork always-on agent service. The daemon launches Claude Code with unattended permission bypass enabled.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/tasks/scheduler.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/version.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/util/paths.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/doctor.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/cli/commands.jsView on unpkg · L245Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L22Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L22Package source references child process execution.
dist/tasks/scheduler.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/version.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/util/paths.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/doctor.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/cli/commands.jsView on unpkg · L245