vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-RJCZJB5M.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/chunk-NCAFOE7Q.jsView on unpkg · L459Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-JQCCIPWS.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/chunk-JQCCIPWS.jsView on unpkg · L7Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L26Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunk-L5H6FZSF.jsView on unpkg · L32Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-L5H6FZSF.jsView on unpkg · L32A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-EL2PYD6E.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-75ZZ4EJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgThis report applies to @vibgrate/cli@2026.1005.1.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L95A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L26Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Package source references child process execution.
dist/chunk-RJCZJB5M.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L26Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunk-L5H6FZSF.jsView on unpkg · L32Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-L5H6FZSF.jsView on unpkg · L32A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-EL2PYD6E.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-75ZZ4EJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgPackage source references dynamic require/import behavior.
dist/chunk-NCAFOE7Q.jsView on unpkg · L459Package source references weak cryptographic algorithms.
dist/chunk-JQCCIPWS.jsView on unpkg · L7Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-JQCCIPWS.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L95A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L26