AI Coding Token Economizer & Model Fatigue Shield for Cursor, Claude Code, Windsurf & VS Code
LPM flags this version as an AI-agent control-surface risk. An automatic silent postinstall modifies user-level configurations across multiple AI agents. It registers the package as an executable MCP server without consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/cli.jsView on unpkg · L24A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L11A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/cli.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/cli.jsView on unpkg · L11Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
core/audio_context_compressor.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/setup_agent_tools.shView on unpkgThis report applies to tokenshield-contextplus@1.0.13.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Package ships non-JavaScript build or shell helper files.
core/audio_context_compressor.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/setup_agent_tools.shView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/cli.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
bin/cli.jsView on unpkg · L24Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/cli.jsView on unpkg · L11Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
bin/cli.jsView on unpkg