NanoCorp CLI: create and run your autonomous company from the terminal.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically invokes a native binary to install skills into third-party coding-agent control surfaces. The operation is silent and defaults to enabled.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs a postinstall lifecycle hook automatically.
package.jsonView on unpkg · L15Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe hook silently launches the bundled CLI with a skills-install command.
scripts/postinstall.jsView on unpkg · L9This report applies to nanocorp@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16The package runs a postinstall lifecycle hook automatically.
package.jsonView on unpkg · L15Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe hook silently launches the bundled CLI with a skills-install command.
scripts/postinstall.jsView on unpkg · L9