SQLite-backed MCP memory server (MindBrain + Zig backend), part of the MindBrain ecosystem.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically changes consumer-project files and existing user AI-agent configuration. It registers a Ghostcrab MCP server in Cursor and Codex configuration without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/lib/prebuild-permissions.mjsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/lib/install-upgrade.mjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lib/install-upgrade.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/lib/sqlite-file-count.mjsView on unpkg · L2Package source references weak cryptographic algorithms.
dist/tools/business-query-learning/register-proposal.jsView on unpkg · L245A manifest entrypoint or package-local install chain reaches persistence behavior.
bin/lib/path-shim.mjsView on unpkg · L23Source writes installer persistence such as shell profile or service configuration.
bin/lib/path-shim.mjsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/commands/serve.mjsView on unpkg · L314Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/commands/serve.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/lib/mcp-permissions-adapters.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
docs/installers/beta-bundle/MakefileView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lib/brain-engine-runner.mjsView on unpkgThis report applies to @mindflight/ghostcrab-personal-mcp@0.6.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L63Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/lib/mcp-permissions-adapters.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
docs/installers/beta-bundle/MakefileView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lib/brain-engine-runner.mjsView on unpkgPackage source references child process execution.
bin/lib/prebuild-permissions.mjsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/lib/install-upgrade.mjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/lib/install-upgrade.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/lib/sqlite-file-count.mjsView on unpkg · L2Package source references weak cryptographic algorithms.
dist/tools/business-query-learning/register-proposal.jsView on unpkg · L245Source writes installer persistence such as shell profile or service configuration.
bin/lib/path-shim.mjsView on unpkg · L23A manifest entrypoint or package-local install chain reaches persistence behavior.
bin/lib/path-shim.mjsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/commands/serve.mjsView on unpkg · L314Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/commands/serve.mjsView on unpkg