The production framework for self-improving & self-organizing LLM knowledge vaults — grounding invariants, code drift detection, auto-skillification, and 1-click multi-agent setup.
LPM flags this version as an AI-agent control-surface risk. Installing the package invokes a postinstall script that copies an agent skill into detected cross-vendor agent directories. It also creates a project .agents skill directory when none is present.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs scripts/install.js automatically as postinstall.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L36package.json runs scripts/install.js automatically as postinstall.
package.jsonView on unpkg · L32Package ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkg