让任意 AI Agent 直接调用 focalapi 创作模型的命令行工具
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically adds bundled FocalAPI skills to detected AI-agent skill directories. This is a first-party extension lifecycle mutation, without a confirmed exfiltration or remote-payload chain.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material through DNS lookups.
dist/cli.jsView on unpkg · L41A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L26Source appears to send environment or credential material through DNS lookups.
dist/cli.jsView on unpkg · L41A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkg