LeanCTX — a local Context SDK for AI agents. Select, shape, reuse, recover, and measure context before inference. No Rust required.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package downloads an unpinned latest native release, installs it into the package, and invokes its onboarding command. The downloaded executable is not available for source inspection and may alter AI-tool configuration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-named source file stages remote content through filesystem writes and execution.
postinstall.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
postinstall.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
preinstall.jsView on unpkgThis report applies to lean-ctx-bin@3.10.2.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
postinstall.jsView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L30Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
postinstall.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
preinstall.jsView on unpkgInstall-named source file stages remote content through filesystem writes and execution.
postinstall.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
postinstall.jsView on unpkg