Loop Engineering CLI — workflow primitive / loop guards / evaluators / slice orchestration
LPM flags this version as an AI-agent control-surface risk. Installing the package executes a postinstall hook that installs package-controlled skills, agents, and output styles into broad third-party AI-agent control surfaces. It also sets Claude Code's active output style and can launch an automatic project upgrade.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/shared/process.jsView on unpkg · L1Package source references shell execution.
dist/services/upgrade/upgrade-service.jsView on unpkg · L182Package source references dynamic require/import behavior.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkg · L151Package source references weak cryptographic algorithms.
dist/services/code/job-shape-decision.jsView on unpkg · L92Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/hooks-commands.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli/commands/playwright-commands.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/playwright-commands.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/code-review/ocr-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/artifacts/artifact-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/runtime/vendors/codex.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/runtime/vendors/copilot.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L135Package source references child process execution.
dist/shared/process.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/hooks-commands.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/code-review/ocr-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/artifacts/artifact-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/runtime/vendors/codex.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/runtime/vendors/copilot.jsView on unpkgPackage source references shell execution.
dist/services/upgrade/upgrade-service.jsView on unpkg · L182Package source references dynamic require/import behavior.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkg · L151Package source references weak cryptographic algorithms.
dist/services/code/job-shape-decision.jsView on unpkg · L92Package source invokes a package manager install command at runtime.
dist/cli/commands/playwright-commands.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/playwright-commands.jsView on unpkg