Roleflow: sistema OpenCode portable con roles por responsabilidad + routing barato + ahorro de tokens. Público, instalable desde cualquier PC o server con una línea en opencode.json.
LPM flags this version as an AI-agent control-surface risk. Installation automatically writes agent instructions and skills into shared global OpenCode configuration. These writes are neither restricted to a roleflow namespace nor guarded by explicit consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs postinstall.mjs during installation.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall.mjs targets the user's global OpenCode agents and skills directories.
postinstall.mjsView on unpkg · L9The hook recursively copies package content into those shared directories without consent or collision checks, allowing existing agent instructions to be overwritten.
postinstall.mjsView on unpkg · L13This report applies to roleflow@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21package.json automatically runs postinstall.mjs during installation.
package.jsonView on unpkg · L20postinstall.mjs targets the user's global OpenCode agents and skills directories.
postinstall.mjsView on unpkg · L9The hook recursively copies package content into those shared directories without consent or collision checks, allowing existing agent instructions to be overwritten.
postinstall.mjsView on unpkg · L13