Fractal memory system for OpenCode with semantic search and automatic compression.
LPM treats this as warn-only first-party agent extension lifecycle risk. Plugin initialization installs package-owned agent and command files globally with forced replacement. This creates an extension lifecycle risk, but no confirmed malicious attack was established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
management/public/d3.min.jsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/clean-plugin-installs.tsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/opencode-backup.shView on unpkgPackage ships high-entropy non-source blobs.
management/public/models/brain-atlas.glbView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/management-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
management/public/vendor/viz-global.jsView on unpkgThis report applies to opencode-fractal-memory@0.8.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L41Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/clean-plugin-installs.tsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/opencode-backup.shView on unpkgPackage ships high-entropy non-source blobs.
management/public/models/brain-atlas.glbView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/management-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
management/public/vendor/viz-global.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
management/public/d3.min.jsView on unpkg · L1