CLI scaffolding tool for domain-driven feature folders in Next.js, React, Node, and NestJS projects, with per-action files, bespoke actions, and agent guidance
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies AI-agent instruction and skill files in the consuming project. This is a foreign, broad AI-agent control-surface mutation without an explicit user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers an automatic postinstall hook.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/init/init.jsView on unpkg · L1The postinstall launcher invokes its bundled code and suppresses errors.
scripts/postinstall.jsView on unpkg · L1This report applies to domain-driver@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21The package registers an automatic postinstall hook.
package.jsonView on unpkg · L17Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/init/init.jsView on unpkg · L1The postinstall launcher invokes its bundled code and suppresses errors.
scripts/postinstall.jsView on unpkg · L1