Persist and reuse work context across chats, projects, and tools via MCP and CLI
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm install mutates Cursor's MCP configuration and adds Continuum-managed Cursor commands. This causes Cursor to launch the package's local MCP server after reload.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/postinstall.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L1Setup creates/updates ~/.cursor/mcp.json with a local Continuum MCP server.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L15Global-install postinstall automatically runs Cursor setup.
dist/infrastructure/cursor/postinstall.jsView on unpkg · L3Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33Package source references dynamic require/import behavior.
scripts/postinstall.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L1Setup creates/updates ~/.cursor/mcp.json with a local Continuum MCP server.
dist/infrastructure/cursor/CursorMcpConfig.jsView on unpkg · L15Global-install postinstall automatically runs Cursor setup.
dist/infrastructure/cursor/postinstall.jsView on unpkg · L3