npx/bunx installer for the LitHermes Hermes plugin
LPM treats this as warn-only first-party agent extension lifecycle risk. A user-invoked installer deploys an auto-loaded Hermes extension. Its pre-LLM lifecycle hook can perform a bounded automatic npm update on an interactive first turn; no install-time npm hook is present.
Package source references dynamic require/import behavior.
bin/lithermes.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
assets/lithermes-plugin/litgoal/store.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/lithermes-plugin/skills/lit-scientific-visualization/original/045_scientific-visualization/tests/test_figure_export.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/lithermes-plugin/skills/programming/scripts/typescript/check-no-excuse-rules.tsView on unpkgPackage source references dynamic require/import behavior.
bin/lithermes.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
assets/lithermes-plugin/litgoal/store.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
assets/lithermes-plugin/skills/lit-scientific-visualization/original/045_scientific-visualization/tests/test_figure_export.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/lithermes-plugin/skills/programming/scripts/typescript/check-no-excuse-rules.tsView on unpkg