Claude Code-style persistent memory for OpenCode — plain markdown, no vector DB
LPM flags this version as an AI-agent control-surface risk. On package installation, the lifecycle hook writes executable tool files into the user-wide OpenCode tools directory. Those tools extend an AI agent with persistent-memory read, write, search, and deletion capabilities.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package declares an automatic postinstall lifecycle hook.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/storage.ts#virtual:normalized:round1View on unpkgThat hook creates the user-wide OpenCode tools directory and copies every shipped TypeScript tool into it without an explicit user command.
postinstall.mjsView on unpkg · L15The tool maps global-scope memory to the user's OpenCode configuration directory.
tools/memory_write.tsView on unpkg · L21This report applies to opencode-memd@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L12The package declares an automatic postinstall lifecycle hook.
package.jsonView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/storage.ts#virtual:normalized:round1View on unpkgThat hook creates the user-wide OpenCode tools directory and copies every shipped TypeScript tool into it without an explicit user command.
postinstall.mjsView on unpkg · L15The tool maps global-scope memory to the user's OpenCode configuration directory.
tools/memory_write.tsView on unpkg · L21