The reference architecture for LLM-maintained knowledge vaults ??schema, lifecycle loop, machine verification, self-installation. Installs the wiki-manager skill into your agent runtime (Claude Code, Codex CLI, opencode).
LPM flags this version as an AI-agent control-surface risk. npm postinstall automatically copies a skill into detected AI-agent runtime directories. It force-overwrites the destination and activates after the runtime restarts.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgRuntime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L36Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkg