Intelligent context window optimization for Claude Code - store content externally via caching and compression, freeing up your context window for what matters
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically installs always-on AI-agent hooks and alters broad AI-client control surfaces. It also marks the current Claude workspace trusted.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
hooks-core/skeleton.mjsView on unpkg · L29Package source references shell execution.
dist/tools/build-systems/run-node-bin.jsView on unpkg · L9Package source references a known benign dynamic code generation pattern.
dist/tools/code-analysis/smart-security.jsView on unpkg · L162Package source references dynamic require/import behavior.
dist/tools/intelligence/wiki-write.jsView on unpkg · L70Package source references weak cryptographic algorithms.
dist/tools/configuration/smart-env.jsView on unpkg · L98A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/verify-wiki-ui.mjsView on unpkg · L123Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
plugin/hooks/lib/restore.mjsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
install-hooks.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/analysis/project-analyzer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli-wrapper.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/build-systems/smart-docker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/build-systems/smart-network.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/code-analysis/smart-imports.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L30Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L30Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
plugin/hooks/lib/restore.mjsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
install-hooks.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/analysis/project-analyzer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli-wrapper.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/build-systems/smart-docker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/build-systems/smart-network.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/code-analysis/smart-imports.jsView on unpkgPackage source references child process execution.
hooks-core/skeleton.mjsView on unpkg · L29Package source references shell execution.
dist/tools/build-systems/run-node-bin.jsView on unpkg · L9Package source references a known benign dynamic code generation pattern.
dist/tools/code-analysis/smart-security.jsView on unpkg · L162Package source references dynamic require/import behavior.
dist/tools/intelligence/wiki-write.jsView on unpkg · L70Package source references weak cryptographic algorithms.
dist/tools/configuration/smart-env.jsView on unpkg · L98A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/verify-wiki-ui.mjsView on unpkg · L123