Multi-agent orchestration and Codex governance for OpenCode, Hermes, Grok Build, and OpenClaw
LPM flags this version as an AI-agent control-surface risk. npm postinstall rewrites the consumer project agent files and, when HOME is the real user home, also writes Hermes and OpenClaw control files under that home. It enables those plugins and installs an OpenClaw pre-tool hook.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/security/security-scanner.jsView on unpkg · L6Package source references dynamic require/import behavior.
dist/core/boot-orchestrator.jsView on unpkg · L172Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/node/postinstall.cjsView on unpkg · L39Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/scripts/pre-command.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/foundry/mint-suit.cjsView on unpkgPackage source invokes a package manager install command at runtime.
dist/integrations/grok/grok-cli.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/grok/grok-cli.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/integrations/hermes-agent/conftest.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.opencode/init.shView on unpkgA package entrypoint or install-reachable source explicitly loads and activates an executable-looking payload from a test, fixture, or hidden path.
dist/cli/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/framework-logger.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/node/bridge-mcp-wiring.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/mcp-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/skill-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/hooks/pipeline-hook-runtime.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/node/install-bridges.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/govern.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/execution/opencode-cli-invoker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/plugins/plugin-integration.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mcps/boot-orchestrator.server.jsView on unpkgThis report applies to 0xray@4.0.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L92Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L92Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/scripts/pre-command.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/foundry/mint-suit.cjsView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/integrations/hermes-agent/conftest.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.opencode/init.shView on unpkgA package entrypoint or install-reachable source explicitly loads and activates an executable-looking payload from a test, fixture, or hidden path.
dist/cli/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core/framework-logger.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/node/bridge-mcp-wiring.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/mcp-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/skill-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/hooks/pipeline-hook-runtime.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/node/install-bridges.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/govern.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/execution/opencode-cli-invoker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/plugins/plugin-integration.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mcps/boot-orchestrator.server.jsView on unpkgPackage source references child process execution.
dist/security/security-scanner.jsView on unpkg · L6Package source references dynamic require/import behavior.
dist/core/boot-orchestrator.jsView on unpkg · L172Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/node/postinstall.cjsView on unpkg · L39Package source invokes a package manager install command at runtime.
dist/integrations/grok/grok-cli.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/integrations/grok/grok-cli.jsView on unpkg