Conversational workspaces, agents and workflows for AI assistants.
LPM flags this version as an AI-agent control-surface risk. Automatic installation modifies the consumer project's shared assistant instructions, prompt hooks, and command permissions without asking for consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
init-project.mjsView on unpkg · L21Package source references a known benign dynamic code generation pattern.
onboarding/skills/premium-web-design/tests/reveal.browser.check.mjsView on unpkg · L32Package source references dynamic require/import behavior.
runtime/scope-verify.mjsView on unpkg · L39Package source executes code through a VM context API.
onboarding/skills/premium-web-design/tests/integrity.check.mjsView on unpkg · L8Package source invokes a package manager install command at runtime.
agent-kit/hooks/scope-guard.mjsView on unpkg · L1122A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
runtime/catalog-index.mjs#virtual:string-array:round1View on unpkgThis report applies to brainforge-kit@0.3.0-beta.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
runtime/catalog-index.mjs#virtual:string-array:round1View on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
init-project.mjsView on unpkg · L21Package source references a known benign dynamic code generation pattern.
onboarding/skills/premium-web-design/tests/reveal.browser.check.mjsView on unpkg · L32Package source references dynamic require/import behavior.
runtime/scope-verify.mjsView on unpkg · L39Package source executes code through a VM context API.
onboarding/skills/premium-web-design/tests/integrity.check.mjsView on unpkg · L8Package source invokes a package manager install command at runtime.
agent-kit/hooks/scope-guard.mjsView on unpkg · L1122