Is yvgude/lean-ctx safe?
Use with caution. yvgude/lean-ctx is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the lean-ctx skill by yvgude a trust score of 74/100 with 9 findings (2 high).
https://github.com/yvgude/lean-ctx
Is yvgude/lean-ctx safe to install?
lean-ctx is a legitimate, professionally developed AI context optimization SDK that functions as an MCP server and LLM API proxy. While no active malicious behavior was observed during clone and no canary files were exfiltrated, the skill carries meaningful CAUTION-level risks: an always-active Kiro steering document that mandatorily overrides agent behavior, a review sub-skill that reads live Claude Code session transcripts and can file findings to the author's GitHub repository, npm preinstall/postinstall scripts that execute during installation, and a full LLM API proxy that intercepts all agent-AI traffic. These are documented features rather than hidden attacks, but they represent unusual levels of access and behavioral control that warrant user awareness before installation.
What security issues were found in yvgude/lean-ctx?
Category Scores
Findings (9)
HIGH Always-Active Kiro Steering Forces Mandatory Agent Behavior Override -20 ▶
The file rust/.kiro/steering/lean-ctx.md uses 'inclusion: always' which means it is automatically prepended to every Kiro agent session in any workspace where lean-ctx is installed. It contains 'You MUST prefer lean-ctx tools over native equivalents' - a mandatory behavioral override that routes all file reads, shell executions, and searches through lean-ctx without user awareness or consent per session.
HIGH lean-ctx-review Skill Reads Claude Code Live Session Transcripts -18 ▶
The lean-ctx-review skill explicitly instructs agents to read ~/.claude/projects//.jsonl files - these are Claude Code's raw conversation history files containing all messages, tool calls, code snippets, and potentially sensitive data from active sessions. The skill also provides a Python script (scripts/scan_session.py) to parse and analyze this data, and can then file GitHub issues to the skill author's repository (yvgude/lean-ctx) with findings derived from this data.
MEDIUM npm Preinstall and Postinstall Scripts Execute During Package Installation -15 ▶
The lean-ctx-bin npm package includes both preinstall and postinstall hooks (node preinstall.js and node postinstall.js). These execute automatically during npm install without explicit user acknowledgment. While binary download via postinstall is a common pattern (used by esbuild, etc.), the content of these scripts was not included in the evidence for inspection, and they represent code execution that occurs before the user has fully consented.
MEDIUM curl-pipe-bash Remote Code Execution in Setup Instructions -12 ▶
SKILL.md instructs agents to run the following if lean-ctx is not found: curl -fsSL https://raw.githubusercontent.com/yvgude/lean-ctx/main/skills/lean-ctx/scripts/install.sh | bash. An agent following this instruction will silently download and execute arbitrary shell code from the internet. The install script content is not included in the cloned repo evidence, making it impossible to audit statically.
MEDIUM LLM API Proxy Intercepts All Agent-AI Communications -12 ▶
The skill includes a full-featured API proxy (src/proxy/) that intercepts requests to Anthropic, OpenAI, Google, Bedrock, and other providers. When active, this proxy has full read/write access to all prompt content sent to and from the LLM. The proxy can compress, route, modify, and log all traffic. This creates a persistent man-in-the-middle position for all agent AI interactions.
MEDIUM AUR Submodule References External Package Repository -8 ▶
The .gitmodules file declares a submodule at aur/lean-ctx-bin pointing to ssh://[email protected]/lean-ctx-bin.git. The AUR (Arch User Repository) is maintained separately from the main repo and can be updated independently. If submodules are initialized, code from this external source could execute. AUR packages in particular have a history of supply chain compromises.
LOW Cloud OCLA API Telemetry and Savings Ledger -8 ▶
The OCLA (Open Context & Token Lifecycle Architecture) system uploads savings data, telemetry, usage patterns, and agent interaction metrics to lean-ctx's cloud backend. SKILL.md references 'lean-ctx gain', 'lean-ctx wrapped', and analytics endpoints. The scope of data transmitted (token counts, model names, interaction patterns, timing) could reveal sensitive information about agent usage workflows.
LOW lean-ctx setup Modifies Agent Integration Configuration -5 ▶
The 'lean-ctx setup' command installs 'shell hook + editor wiring + rules + skills' and 'lean-ctx init --agent claude' configures Claude Code integration. These commands modify persistent system configuration that affects how the agent operates in future sessions, not just the current one. An agent following setup instructions will reconfigure its own operating environment.
INFO Legitimate OSS Software with Unusually Broad System Access Scope -5 ▶
lean-ctx is a professionally maintained, well-tested, Apache-2.0 licensed context optimization tool with genuine utility. However, it is architected to occupy a uniquely privileged position: acting as proxy for all LLM API traffic, reading shell history, intercepting tool calls, reading session transcripts, and modifying agent behavioral defaults. No single malicious intent is evident, but the combination of access capabilities represents substantial risk if the skill or its infrastructure were compromised.
Should I install yvgude/lean-ctx?
Oathe's verdict for yvgude/lean-ctx is CAUTION with a trust score of 74/100. Recommendation: Install with caution.