vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)
Running the CLI automatically retrieves an unpinned latest auxiliary package and later imports its JavaScript. The package therefore provides a registry-controlled remote-code execution path outside npm's normal locked dependency graph.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-CXX7LSQ6.jsView on unpkgPackage source references dynamic require/import behavior.
dist/fastembed-CXX7LSQ6.jsView on unpkg · L19Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-6SLWNAJH.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/chunk-6SLWNAJH.jsView on unpkg · L7Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L45A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L45A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-LMTTDOIC.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-BSV56IQB.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YGOMCQPX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WZ5IOZRJ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.d.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-QGBQXXRU.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-UWYBNKJ6.jsView on unpkgThis report applies to @vibgrate/cli@2026.916.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L45Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L91Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L45A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L45Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L45A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L45A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-LMTTDOIC.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-BSV56IQB.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YGOMCQPX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZRPXTSMX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WZ5IOZRJ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-YJCBWHKW.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.d.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-LEEXGKZH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-QGBQXXRU.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-UWYBNKJ6.jsView on unpkgPackage source references child process execution.
dist/chunk-EZ7UC5Y5.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/fastembed-CXX7LSQ6.jsView on unpkg · L19Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/fastembed-CXX7LSQ6.jsView on unpkgPackage source references weak cryptographic algorithms.
dist/chunk-6SLWNAJH.jsView on unpkg · L7Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/chunk-6SLWNAJH.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L45Source exposes local file and command tools to a remote model endpoint.
dist/cli.jsView on unpkg · L91Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L45A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L45