NanoCorp CLI: create and run your autonomous company from the terminal.
LPM treats this as warn-only first-party agent extension lifecycle risk. The postinstall hook automatically invokes the package CLI to install bundled skills into supported agent skill directories. This is first-party package-owned agent extension setup.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package defines an automatic postinstall hook.
package.jsonView on unpkg · L15Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe CLI selects and runs a vendored platform executable; its behavior was not readable during source inspection.
bin/nanocorp.jsView on unpkg · L16The hook runs the package’s own CLI to install bundled agent skills unless an opt-out variable is set.
scripts/postinstall.jsView on unpkg · L8This report applies to nanocorp@0.3.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16The package defines an automatic postinstall hook.
package.jsonView on unpkg · L15The CLI selects and runs a vendored platform executable; its behavior was not readable during source inspection.
bin/nanocorp.jsView on unpkg · L16Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/nanocorp.jsView on unpkgThe hook runs the package’s own CLI to install bundled agent skills unless an opt-out variable is set.
scripts/postinstall.jsView on unpkg · L8