A self-evolving workflow management system for AI agent development
LPM flags this version as an AI-agent control-surface risk. npm postinstall mutates the consumer project and writes GitHub Copilot instructions derived from package templates. This is an unconsented foreign AI-agent control-surface write.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WK7D2AVV.jsView on unpkgPackage source references dynamic require/import behavior.
dist/chunk-WK7D2AVV.jsView on unpkg · L214Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/chunk-JRXA6XDA.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L53Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L53Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/chunk-JRXA6XDA.jsView on unpkgPackage source references dynamic require/import behavior.
dist/chunk-WK7D2AVV.jsView on unpkg · L214Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WK7D2AVV.jsView on unpkg