MCP plugin that saves 98% of your context window. Works with Claude Code, Gemini CLI, VS Code Copilot, OpenCode, and Codex CLI. Sandboxed code execution, FTS5 knowledge base, and intent-driven search.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation can automatically enable and repair the package's Claude Code extension. This establishes a package-owned extension lifecycle risk, without a confirmed malicious attack.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/statusline.mjsView on unpkg · L30Package source references dynamic require/import behavior.
bin/statusline.mjsView on unpkg · L56Source executes local commands and sends command output to an external endpoint.
server.bundle.mjsView on unpkg · L184Source passes code obtained from a remote response into a dynamic execution sink.
server.bundle.mjsView on unpkg · L2Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
build/adapters/codex/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
build/cli.jsView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
build/cli.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.bundle.mjsView on unpkg · L488A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
cli.bundle.mjsPackage source invokes a package manager install command at runtime.
scripts/heal-better-sqlite3.mjs#virtual:normalized:round1View on unpkg · L149A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/statusline.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/adapters/pi/mcp-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/executor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/platform-bridge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/heal-better-sqlite3.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/adapters/cursor/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/db-base.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/session-db.bundle.mjsView on unpkgThis report applies to @mxalbert/context-mode@2.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
server.bundle.mjsView on unpkg · L5Source reaches cloud instance metadata or link-local credential endpoints.
server.bundle.mjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.bundle.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L103Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L103Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgSource executes local commands and sends command output to an external endpoint.
server.bundle.mjsView on unpkg · L184Source passes code obtained from a remote response into a dynamic execution sink.
server.bundle.mjsView on unpkg · L2Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
build/adapters/codex/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
build/cli.jsView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
build/cli.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.bundle.mjsView on unpkg · L488A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
cli.bundle.mjsPackage source invokes a package manager install command at runtime.
scripts/heal-better-sqlite3.mjs#virtual:normalized:round1View on unpkg · L149A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/statusline.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/adapters/pi/mcp-bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/executor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/platform-bridge.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/heal-better-sqlite3.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/adapters/cursor/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/db-base.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/session-db.bundle.mjsView on unpkgPackage source references child process execution.
bin/statusline.mjsView on unpkg · L30Package source references dynamic require/import behavior.
bin/statusline.mjsView on unpkg · L56A single source file combines environment access, network access, and code or shell execution; review context before blocking.
server.bundle.mjsView on unpkg · L5Source reaches cloud instance metadata or link-local credential endpoints.
server.bundle.mjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.bundle.mjsView on unpkg