Local runtime and Agent integration for traceable knowledge production
LPM treats this as warn-only first-party agent extension lifecycle risk. Global installation automatically refreshes first-party agent plugins and provider skills. This creates an agent extension lifecycle risk, but the inspected behavior does not establish a confirmed malicious attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgThis report applies to @c4a/context-cli@0.7.29.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L61Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L61Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkg