Persist and reuse work context across chats, projects, and tools via MCP and CLI
LPM treats this as warn-only first-party agent extension lifecycle risk. A global install automatically configures Cursor to launch the bundled local MCP server and adds Continuum slash commands. This is a first-party Cursor extension setup, not a remote payload or credential-exfiltration chain.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/postinstall.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L1Global-install postinstall imports Cursor setup.
dist/infrastructure/cursor/postinstall.jsView on unpkg · L3Setup writes a Continuum MCP entry to Cursor config.
dist/infrastructure/cursor/CursorMcpConfigWriter.jsView on unpkg · L18Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33Package source references dynamic require/import behavior.
scripts/postinstall.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L1Global-install postinstall imports Cursor setup.
dist/infrastructure/cursor/postinstall.jsView on unpkg · L3Setup writes a Continuum MCP entry to Cursor config.
dist/infrastructure/cursor/CursorMcpConfigWriter.jsView on unpkg · L18