inplan — a Markdown editor for human ⇄ coding-agent planning. CLI + desktop editor.
LPM flags this version as an AI-agent control-surface risk. npm postinstall mutates installed AI-agent control surfaces. It installs persistent hooks/extensions that capture agent output and tool activity and can relay it to a cloud document.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L3Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
app/renderer/assets/index-CJjtgrEi.jsView on unpkg · L27292A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/renderer/assets/index-CJjtgrEi.jsView on unpkgPackage source references dynamic require/import behavior.
app/renderer/assets/index-CJjtgrEi.jsView on unpkg · L47701Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/cli.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/main/index.cjsView on unpkg · L898Package source references weak cryptographic algorithms.
app/main/index.cjsView on unpkg · L2Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L3Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25Package source references child process execution.
app/renderer/assets/index-CJjtgrEi.jsView on unpkg · L27292A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/renderer/assets/index-CJjtgrEi.jsView on unpkgPackage source references dynamic require/import behavior.
app/renderer/assets/index-CJjtgrEi.jsView on unpkg · L47701Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/cli.jsView on unpkg · L6Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/cli.jsView on unpkg · L3Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkgPackage source references weak cryptographic algorithms.
app/main/index.cjsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/main/index.cjsView on unpkg · L898