<p align="center"> <img src="https://img.shields.io/badge/python-3.11%2B-3776AB?style=flat-square&logo=python&logoColor=white" alt="Python 3.11+"> <img src="https://img.shields.io/badge/license-GPL--3.0-491?style=flat-square" alt="License: GPL-3.0">
LPM flags this version as an AI-agent control-surface risk. The automatic postinstall handler changes the consumer project's npm script approval policy. It approves every installed package it finds with a preinstall, install, or postinstall script.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/lib/extension-debug-harness.tsView on unpkg · L137Package ships non-JavaScript build or shell helper files.
scripts/pi-usereq-debug.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/core/pi-notify.tsView on unpkgThis report applies to pi-usereq@0.58.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Package ships non-JavaScript build or shell helper files.
scripts/pi-usereq-debug.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/core/pi-notify.tsView on unpkgPackage source references dynamic require/import behavior.
scripts/lib/extension-debug-harness.tsView on unpkg · L137