Local runtime and Agent integration for traceable knowledge production
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm install automatically refreshes this package's agent integrations. This creates a first-party agent-extension lifecycle risk, but no confirmed credential theft, remote payload execution, or destructive attack was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgThis report applies to @c4a/context-cli@0.7.26.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L61Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L61Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkg