Agentic coding setup framework audited each release across 24 governance domains. One command to hatch your agent stack -- agents, skills, rules, commands, and MCP for Claude Code, Cursor, and GitHub Copilot.
LPM treats this as warn-only first-party agent extension lifecycle risk. The CLI can install first-party agent configuration into a repository only after an explicit user command. Opt-in MCP configuration may later launch pinned third-party tools or contact GitHub using a user-provided token; no unconsented install-time action is present.
Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/cli/index.jsView on unpkg · L1096A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/cli/index.jsView on unpkg · L17Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/cli/index.jsView on unpkg · L1096A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/cli/index.jsView on unpkg · L17