Multi-agent orchestration for Claude Code — parallel review, consensus, adaptive dispatch
LPM treats this as warn-only first-party agent extension lifecycle risk. Npm installation silently registers Gossipcat in the consuming project's MCP configuration. An MCP host that loads that configuration can subsequently launch the bundled server.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time source drops package-supplied AI-agent/MCP control files or instructions.
scripts/postinstall.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
assets/hooks/discipline/pretool-signals-validate.shView on unpkgPackage ships high-entropy non-source blobs.
dist-dashboard/assets/Geist-Variable-jflMhO5d.woff2View on unpkgPackage contains source files above the static scanner size ceiling.
dist-mcp/mcp-server.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist-mcp/mcp-server.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L36Package ships non-JavaScript build or shell helper files.
assets/hooks/discipline/pretool-signals-validate.shView on unpkgPackage ships high-entropy non-source blobs.
dist-dashboard/assets/Geist-Variable-jflMhO5d.woff2View on unpkgPackage contains source files above the static scanner size ceiling.
dist-mcp/mcp-server.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist-mcp/mcp-server.jsView on unpkgInstall-time source drops package-supplied AI-agent/MCP control files or instructions.
scripts/postinstall.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg