vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/chunk-2JGSNRSI.jsView on unpkg · L72Package source references weak cryptographic algorithms.
dist/chunk-GD7PFQIG.jsView on unpkg · L12Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L26Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-JQCCIPWS.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-5P4U6B77.jsView on unpkg · L32A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-7GJP2T46.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-75ZZ4EJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgThis report applies to @vibgrate/cli@2026.1006.1.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L96A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L26Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L26Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-JQCCIPWS.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-5P4U6B77.jsView on unpkg · L32A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-7GJP2T46.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-75ZZ4EJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/chunk-2JGSNRSI.jsView on unpkg · L72Package source references weak cryptographic algorithms.
dist/chunk-GD7PFQIG.jsView on unpkg · L12This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L96A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L26