Persistent self-improving agent memory — install & forget: auto-inject context via git hooks, zero-arg bootstrap, machine-wide global vault, 13 memory types, confidence tracking, XML codebase graphs
LPM flags this version as an AI-agent control-surface risk. npm postinstall silently modifies the consuming project’s AI-agent configuration and instruction surfaces. It registers agentic-cortex-mcp and injects mandatory agent instructions without user action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Package source references dynamic require/import behavior.
preload.jsView on unpkg · L6Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L30Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references dynamic require/import behavior.
preload.jsView on unpkg · L6Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/create-discovery-files.jsView on unpkg