Local runtime and Agent integration for traceable knowledge production
LPM flags this version as an AI-agent control-surface risk. A global npm install runs postinstall, which launches plugin install for Claude, Codex, and Cursor. That command writes user-level agent plugin configuration and skill directories without a separate plugin command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgThis report applies to @c4a/context-cli@0.7.35.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L61Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L61Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkg