Roleflow: sistema OpenCode portable con roles por responsabilidad + routing barato + ahorro de tokens. Público, instalable desde cualquier PC o server con una línea en opencode.json.
LPM treats this as warn-only first-party agent extension lifecycle risk. The install hook and plugin activation copy bundled agent and skill files into the OpenCode user configuration directory. This is package-owned agent setup and presents lifecycle risk, but the inspected code does not establish a confirmed attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook runs a package script that copies bundled agents and skills into the OpenCode user configuration directory.
package.jsonView on unpkg · L27The postinstall hook runs a package script that copies bundled agents and skills into the OpenCode user configuration directory.
postinstall.mjsView on unpkg · L9The plugin repeats that copy during activation, so package-owned agent setup occurs automatically on install and plugin startup.
dist/index.jsView on unpkg · L55This report applies to roleflow@1.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L30Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L30The postinstall hook runs a package script that copies bundled agents and skills into the OpenCode user configuration directory.
package.jsonView on unpkg · L27The postinstall hook runs a package script that copies bundled agents and skills into the OpenCode user configuration directory.
postinstall.mjsView on unpkg · L9The plugin repeats that copy during activation, so package-owned agent setup occurs automatically on install and plugin startup.
dist/index.jsView on unpkg · L55