ai-paperlantern-code
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Source: https://github.com/paperlantern-ai/paperlantern-cli
Registry: ai.paperlantern/code 0.3.1
Registry: ai.paperlantern/code 0.3.1
Connection signal
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Observed tools
- None observed in this static profile.
Top findings
- Detected capability: shell_execution — src/auth.ts:4
- Detected capability: filesystem_write_delete — src/auth.ts:42
- Install risk pattern: unpinned_dependency — package-lock.json:11
Recommended controls
- Install in a sandbox before team or production use.
- Pin the exact package/repository version.
- Review install scripts, Dockerfile behavior, and dependency pins.
- Do not use production credentials during first install.
- Restrict filesystem, repository, cloud, and database scope.
- Require human approval for destructive actions.