If you think the worst that an agent can do is leak your package.json, your threat model is wayyy broken.