Persistent self-improving agent memory with tree-of-thoughts reasoning: MCTS/beam search, PRM step verification, self-consistency voting, s1 budget forcing, REPL program-aided reasoning, reflexion self-correction, failure classification, experience replay
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically alters the consumer project's AI-agent configuration and instruction files. It also installs Git hooks that invoke the package after common repository events.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/hooks.jsView on unpkg · L185Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
Package ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/failure-classifier.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/manifest.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/repl-executor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/generate-graph.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/bench/locomo.jsView on unpkgThis report applies to agentic-cortex@7.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/cortex-hook.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/import-community-knowledge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/seed-memory-repo.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/failure-classifier.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sync/git-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/auto-setup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/inject-memory.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/manifest.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/repl-executor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/generate-graph.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/bench/locomo.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/hooks.jsView on unpkg · L185Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/create-discovery-files.jsView on unpkg · L5Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/create-discovery-files.jsView on unpkg