Persistent self-improving agent memory with tree-of-thoughts reasoning: MCTS/beam search, PRM step verification, self-consistency voting, s1 budget forcing, REPL program-aided reasoning, reflexion self-correction, 67 MCP tools
LPM flags this version as an AI-agent control-surface risk. On npm installation, the package modifies the consuming project’s AI-agent configuration and instructions without a user command. It also persists CLI execution through Git hooks.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Package source references dynamic require/import behavior.
scripts/demo-nonllm-agent.jsView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
scripts/import-community-knowledge.jsView on unpkg · L750Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgPackage source references dynamic require/import behavior.
scripts/demo-nonllm-agent.jsView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/create-discovery-files.jsView on unpkg