Conversational workspaces, agents and workflows for AI assistants.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies the consumer project's shared AI-agent instructions, hooks, and command permissions. These changes reach Claude and Codex control surfaces without an installation-time consent prompt.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
init-project.mjsView on unpkg · L21This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkgPackage source references shell execution.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkg · L10Package source executes code through a VM context API.
onboarding/skills/premium-web-design/tests/qa-paths.check.mjsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
onboarding/skills/premium-web-design/tests/qa-paths.check.mjsView on unpkg · L429Package source references dynamic require/import behavior.
runtime/scope-verify.mjsView on unpkg · L39Package source invokes a package manager install command at runtime.
agent-kit/hooks/scope-guard.mjsView on unpkg · L1122Source file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-kit/hooks/scope-guard.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
runtime/catalog-index.mjs#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/adapters.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/process.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/fixtures/outcomes/integration-payment-webhook-en/reference/src/webhook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/fixtures/outcomes/integration-payment-webhook-pt-br/reference/src/webhook.mjsView on unpkgThis report applies to brainforge-kit@0.3.0-beta.5.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkg · L131Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Package source invokes a package manager install command at runtime.
agent-kit/hooks/scope-guard.mjsView on unpkg · L1122Source file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-kit/hooks/scope-guard.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
runtime/catalog-index.mjs#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/adapters.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/process.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/fixtures/outcomes/integration-payment-webhook-en/reference/src/webhook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runtime/evals/fixtures/outcomes/integration-payment-webhook-pt-br/reference/src/webhook.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
init-project.mjsView on unpkg · L21Package source references shell execution.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkg · L131This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
onboarding/skills/premium-web-design/scripts/site-check.template.mjsView on unpkgPackage source executes code through a VM context API.
onboarding/skills/premium-web-design/tests/qa-paths.check.mjsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
onboarding/skills/premium-web-design/tests/qa-paths.check.mjsView on unpkg · L429Package source references dynamic require/import behavior.
runtime/scope-verify.mjsView on unpkg · L39