Persistent self-improving agent memory with tree-of-thoughts reasoning: MCTS/beam search, PRM step verification, self-consistency voting, s1 budget forcing, REPL program-aided reasoning, reflexion self-correction, 67 MCP tools
Static analysis flagged 18 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Package source references dynamic require/import behavior.
scripts/demo-nonllm-agent.jsView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/create-discovery-files.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgThis report applies to agentic-cortex@6.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references dynamic require/import behavior.
scripts/demo-nonllm-agent.jsView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/create-discovery-files.jsView on unpkg