vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/fastembed-S6YEJYQV.jsView on unpkg · L19Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L31Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-XAS45W3G.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-5UG4UHKU.jsView on unpkgThis report applies to @vibgrate/cli@2026.819.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L31Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L72Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L31A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L31Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L50Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L50Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L31Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-XAS45W3G.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-5UG4UHKU.jsView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/fastembed-S6YEJYQV.jsView on unpkg · L19Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L31Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L72Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L31A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L31