Audit net MCP context avoided per AI coding agent, optimize context, and share a live local knowledge graph across 16 CLI clients
LPM flags this version as an AI-agent control-surface risk. A global npm postinstall installs persistent hooks into Claude settings, changes workspace trust, and configures MCP servers for multiple AI clients. Those hooks run during later agent sessions and can submit a session digest to a remote model service when an ambient key is available.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
hooks-core/skeleton.mjsView on unpkg · L29Package source references shell execution.
dist/tools/build-systems/run-node-bin.jsView on unpkg · L9Package source references a known benign dynamic code generation pattern.
dist/tools/code-analysis/smart-security.jsView on unpkg · L162Package source references dynamic require/import behavior.
dist/tools/intelligence/wiki-write.jsView on unpkg · L119Package source references weak cryptographic algorithms.
dist/tools/configuration/smart-env.jsView on unpkg · L98A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/capture-screenshots.mjsView on unpkg · L17Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
plugin/hooks/lib/restore.mjsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
install-hooks.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/analysis/project-analyzer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli-wrapper.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks-core/doctor.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks-core/stop-harvest.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
integrations/cline/hooks/token-optimizer/lib/stop-harvest.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L34Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L34Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
plugin/hooks/lib/restore.mjsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
install-hooks.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/analysis/project-analyzer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli-wrapper.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks-core/doctor.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks-core/stop-harvest.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
integrations/cline/hooks/token-optimizer/lib/stop-harvest.mjsView on unpkgPackage source references child process execution.
hooks-core/skeleton.mjsView on unpkg · L29Package source references shell execution.
dist/tools/build-systems/run-node-bin.jsView on unpkg · L9Package source references a known benign dynamic code generation pattern.
dist/tools/code-analysis/smart-security.jsView on unpkg · L162Package source references dynamic require/import behavior.
dist/tools/intelligence/wiki-write.jsView on unpkg · L119Package source references weak cryptographic algorithms.
dist/tools/configuration/smart-env.jsView on unpkg · L98A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/capture-screenshots.mjsView on unpkg · L17