vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)
LPM treats this as warn-only first-party agent extension lifecycle risk. The package can modify project AI-agent configuration, but only through the explicit `vg install` command. Its automatic install hook does not configure agents.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/fastembed-S6YEJYQV.jsView on unpkg · L19Package source references weak cryptographic algorithms.
dist/chunk-BODXEZEY.jsView on unpkg · L20Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L32Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-65YN3BG3.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-HUJZO4K5.jsView on unpkgThis report applies to @vibgrate/cli@2026.829.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L32Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L74Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L32A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L32Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L50Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L50Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L32Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-65YN3BG3.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-HUJZO4K5.jsView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/fastembed-S6YEJYQV.jsView on unpkg · L19Package source references weak cryptographic algorithms.
dist/chunk-BODXEZEY.jsView on unpkg · L20Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L32Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L74Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L32A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L32