Local runtime and Agent integration for traceable knowledge production
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm install automatically runs this package's plugin installer, which registers the bundled c4a agent plugin for Claude, Codex, and Cursor. Local and CI installs skip that path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgThis report applies to @c4a/context-cli@0.7.36.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L61Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L61Package source references dynamic require/import behavior.
parserEntryWorker.jsView on unpkg · L29Source appears to send environment or credential material through DNS lookups.
cli.jsView on unpkg · L35A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
browser/diagrams.jsView on unpkgPackage source references child process execution.
scripts/postinstall.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/postinstall.mjsView on unpkg · L42Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkg