→ Publisher: run `forge publish` from the repo to claim ownership
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface—
Security scan✓ CleanvHEAD · 5d ago
CODE…ures/agent_session.mjsDynamic require of a computed module name
CODE…sures/cache_prefix.mjsDynamic require of a computed module name
CODE…es/exact_estimator.mjsDynamic require of a computed module name
CODE…l_measures/measure.mjsDynamic require of a computed module name
CODE…al_measures/stress.mjsDynamic require of a computed module name
CODE…/tri_engine_rescue.mjsDynamic require of a computed module name
CODE…m-middleware/index.mjsDynamic require of a computed module name
CODE…images-vibe-retina.mjsVery large base64-looking blob in source (in minified file)
CODE…corpus/images-vibe.mjsVery large base64-looking blob in source
CODE…mark/corpus/images.mjsVery large base64-looking blob in source
EvalsNone
IndexedJun 30, 2026
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
About
Offline agentic memory: remember/recall/relate/forget/why over a fused vector+graph+columnar engine