Graph-powered code intelligence for Claude Code. Semantic search + knowledge graph for better AI code understanding.
LPM treats this as warn-only first-party agent extension lifecycle risk. The install hook can alter global instruction files used by multiple AI coding agents. The mutation is guarded by an interactive prompt, but accepting its default changes assistant behavior beyond the installed project.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/cli/services/data/semantic-graph/semantic-graph.jsView on unpkg · L24Package source references child process execution.
dist/shared/post-execution-integration.jsView on unpkg · L12Package source references a known benign dynamic code generation pattern.
dist/shared/intelligent-cycle/services/security-scanning-service.jsView on unpkg · L40Package source references dynamic require/import behavior.
bin/codeseeker.jsView on unpkg · L10Package source references weak cryptographic algorithms.
dist/utils/cache.jsView on unpkg · L179A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/shared/change-assessment-system.jsView on unpkg · L44Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L121Package source invokes a package manager install command at runtime.
dist/cli/quality/compilation-checker.jsView on unpkg · L42A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/mcp/indexing-service.js#virtual:normalized:round1View on unpkgHardcoded password in dist/cli/services/data/semantic-graph/services/graph-storage-service.js
dist/cli/services/data/semantic-graph/services/graph-storage-service.jsView on unpkg · L16This report applies to codeseeker@2.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L20Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.jsView on unpkg · L121Package source invokes a package manager install command at runtime.
dist/cli/quality/compilation-checker.jsView on unpkg · L42A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/mcp/indexing-service.js#virtual:normalized:round1View on unpkgHardcoded password in dist/cli/services/data/semantic-graph/services/graph-storage-service.js
dist/cli/services/data/semantic-graph/services/graph-storage-service.jsView on unpkg · L16Package contains a possible secret pattern.
dist/cli/services/data/semantic-graph/semantic-graph.jsView on unpkg · L24Package source references child process execution.
dist/shared/post-execution-integration.jsView on unpkg · L12Package source references a known benign dynamic code generation pattern.
dist/shared/intelligent-cycle/services/security-scanning-service.jsView on unpkg · L40Package source references dynamic require/import behavior.
bin/codeseeker.jsView on unpkg · L10Package source references weak cryptographic algorithms.
dist/utils/cache.jsView on unpkg · L179A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/shared/change-assessment-system.jsView on unpkg · L44