Agent governance and AI-TDD control plane for requirement-contract-driven Main Agent orchestration, built on BMAD + Spec-Kit
LPM flags this version as an AI-agent control-surface risk. Install-time code targets the consumer project and defaults to the Cursor profile. It creates .cursor/hooks.json and installs commands, rules, skills, agents, and executable hooks that run on Cursor lifecycle events.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/bmad-speckit.jsView on unpkg · L4Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/init-to-root.jsView on unpkg · L8Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/requirements-contract-codex-cli-judge-adapter.test.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
_bmad/runtime/hooks/runtime-policy-inject-core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
_bmad/skills/goal-subcontract-execution-package-generator/scripts/build-execution-package.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/runtime-dashboard-lifecycle-cli.test.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/runtime-dashboard-stable-launcher.test.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/requirements-contract-codex-cli-judge-adapter.test.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
_bmad/runtime/hooks/runtime-policy-inject-core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
_bmad/skills/goal-subcontract-execution-package-generator/scripts/build-execution-package.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/runtime-dashboard-lifecycle-cli.test.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
tests/acceptance/runtime-dashboard-stable-launcher.test.tsView on unpkgPackage source references dynamic require/import behavior.
bin/bmad-speckit.jsView on unpkg · L4Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/init-to-root.jsView on unpkg · L8