Bootstrap and daemon-spawn tool for gm plugkit binary. Downloads the correct platform wasm, verifies SHA256, and launches agentplug-runner (the native wasm host) as the spool watcher daemon.
LPM treats this as warn-only first-party agent extension lifecycle risk. An explicit gm-plugkit CLI run provisions project AI-agent wiring, refreshes global agent skill files, and starts a downloaded native spool daemon. Remote skill content can be written into global AI-agent control paths without a package-pinned trust anchor.
Package source references child process execution.
bootstrap-shared.jsView on unpkg · L5Source downloads or fetches remote code and executes it.
bootstrap.jsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bootstrap.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bootstrap.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgPackage source references child process execution.
bootstrap-shared.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgSource downloads or fetches remote code and executes it.
bootstrap.jsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bootstrap.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bootstrap.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bootstrap.jsView on unpkg