The reference architecture for LLM-maintained knowledge vaults — schema, lifecycle loop, machine verification, self-installation. Installs the wiki-manager skill into your agent runtime (Claude Code, Codex CLI, opencode).
LPM treats this as warn-only first-party agent extension lifecycle risk. npm postinstall deploys the bundled wiki-manager agent skill into already-present global or project runtime directories. No exfiltration or remote execution is present.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5It targets existing global and project AI-agent skill directories.
scripts/install.jsView on unpkg · L20Package ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Package ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5It targets existing global and project AI-agent skill directories.
scripts/install.jsView on unpkg · L20