Your personal FDE in Claude and Codex. Understand the work, use the right tools, deliver and retain useful context. One entry: vibe.
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically modifies AI-agent home configuration and installs package-controlled hooks. It writes instruction cards, skills, and command-hook entries for Claude or Codex.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
mcpb/server/index.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/readerSession.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/core/tree.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/github.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/github.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/global.jsView on unpkg · L17Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install/plugin.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/docs/pdf.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/check-process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/failure.jsView on unpkgThis report applies to @su-record/vibe@4.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install/plugin.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/docs/pdf.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/check-process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/failure.jsView on unpkgPackage source references child process execution.
mcpb/server/index.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/readerSession.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/core/tree.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/github.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/github.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/install/global.jsView on unpkg · L17