Cut your AI coding-agent token usage 60-90%. One command, no code changes.
npm postinstall fetches a remote executable/runtime payload, installs it under ~/.tokenoptimiser, and executes its installer. The shipped source then obscures the installed engine's original branding, leaving its behavior unavailable for source review.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
lib/license.jsView on unpkg · L5Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.jsView on unpkg · L5Package ships non-JavaScript build or shell helper files.
scripts/envscrub.pyView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L13Package ships non-JavaScript build or shell helper files.
scripts/envscrub.pyView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
lib/license.jsView on unpkg · L5Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.jsView on unpkg · L5