Roleflow: sistema OpenCode portable con roles por responsabilidad + routing barato + ahorro de tokens. Público, instalable desde cualquier PC o server con una línea en opencode.json.
LPM treats this as warn-only first-party agent extension lifecycle risk. The npm postinstall hook and plugin startup place Roleflow's bundled agents and skills in the user's OpenCode configuration directory. This is first-party package-owned agent setup and no confirmed malicious attack surface was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook copies the package's agents and skills into the user's OpenCode configuration directory.
package.jsonView on unpkg · L27The postinstall hook copies the package's agents and skills into the user's OpenCode configuration directory.
postinstall.mjsView on unpkg · L9The active plugin also copies those files into that directory whenever it starts.
dist/index.jsView on unpkg · L38The uninstall hook removes a fixed list of Roleflow agent and skill files.
preuninstall.mjsView on unpkg · L6This report applies to roleflow@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L30Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L30The postinstall hook copies the package's agents and skills into the user's OpenCode configuration directory.
package.jsonView on unpkg · L27The postinstall hook copies the package's agents and skills into the user's OpenCode configuration directory.
postinstall.mjsView on unpkg · L9The active plugin also copies those files into that directory whenever it starts.
dist/index.jsView on unpkg · L38The uninstall hook removes a fixed list of Roleflow agent and skill files.
preuninstall.mjsView on unpkg · L6