Loading npm security reports…
Local-first, time-aware journaling memory server over MCP
LPM treats this as warn-only first-party agent extension lifecycle risk. The MCP plugin lifecycle can persist and execute third-party local plugin code in the journal process after an explicit confirmation. No confirmed package-originated exfiltration or install-time attack surface exists.
Package source references dynamic require/import behavior.
dist/kernel/plugin.jsView on unpkg · L60This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/management/module.jsView on unpkgPackage source references dynamic require/import behavior.
dist/kernel/plugin.jsView on unpkg · L60This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/management/module.jsView on unpkg