One memory for the AI you connect. Recall, remember, and revise a brain your agents share — stored in your own folder.
LPM flags this version as an AI-agent control-surface risk. A global npm install emits instructions intended to make an AI agent immediately start browser-based setup. The follow-on setup can install persistent guidance and command hooks into global AI-agent configuration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L15A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L15This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgThis report applies to memgineering@0.19.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L37Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L37Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L15A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L15This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkg