The production framework for self-improving & self-organizing LLM knowledge vaults — grounding invariants, code drift detection, auto-skillification, and 1-click multi-agent setup.
LPM flags this version as an AI-agent control-surface risk. On npm installation, the package mutates detected Claude, OpenCode, Codex/Agents, Cursor, Gemini, CommandCode, and Windsurf skill control surfaces. It replaces the installed wiki-manager skill and prompts the runtime to load it.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpostinstall automatically runs scripts/install.js.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L7Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5Package ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgpostinstall automatically runs scripts/install.js.
package.jsonView on unpkg · L40Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L41Package ships non-JavaScript build or shell helper files.
skills/wiki-manager/scripts/check_evidence.pyView on unpkgPackage source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L7Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.jsView on unpkg · L5