Loop Engineering CLI — workflow primitive / loop guards / evaluators / slice orchestration
LPM flags this version as an AI-agent control-surface risk. npm postinstall mutates multiple AI-agent skill/control directories without an explicit user command. It also sets Claude Code's output style and can trigger a project upgrade.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/shared/process.jsView on unpkg · L1Package source references shell execution.
dist/services/upgrade/upgrade-service.jsView on unpkg · L182Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkgPackage source references dynamic require/import behavior.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkg · L151Package source references weak cryptographic algorithms.
dist/services/code/job-shape-decision.jsView on unpkg · L92Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/hooks-commands.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/cli/commands/playwright-commands.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/playwright-commands.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/services/artifacts/workspace-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/code-review/ocr-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/e2e-verify.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/vm-commands.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L135Package source references child process execution.
dist/shared/process.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/hooks-commands.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/services/artifacts/workspace-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/code-review/ocr-service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/e2e-verify.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/vm-commands.jsView on unpkgPackage source references shell execution.
dist/services/upgrade/upgrade-service.jsView on unpkg · L182Package source references dynamic require/import behavior.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkg · L151Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/governance-classify-contract-commands.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/services/code/job-shape-decision.jsView on unpkg · L92Package source invokes a package manager install command at runtime.
dist/cli/commands/playwright-commands.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/playwright-commands.jsView on unpkg