Multi-agent gateway for Claude
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package can automatically install the bundled MCP extension's dependencies. No credential theft, remote payload execution, or broad foreign agent-control-surface modification was confirmed in the inspected source.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/api/router.jsView on unpkg · L44A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/api/router.jsView on unpkg · L123Source reaches cloud instance metadata or link-local credential endpoints.
mcp/tools/image/module.ts#virtual:normalized:round1View on unpkg · L3Package source invokes a package manager install command at runtime.
dist/api/packages.jsView on unpkg · L225A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/reviewer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/shell/pty-host.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/notifier.jsView on unpkgThis report applies to @0xmaxma/claude-gateway@1.7.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L32Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Source reaches cloud instance metadata or link-local credential endpoints.
mcp/tools/image/module.ts#virtual:normalized:round1View on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/reviewer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/shell/pty-host.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/notifier.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/api/router.jsView on unpkg · L44A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/api/router.jsView on unpkg · L123Package source invokes a package manager install command at runtime.
dist/api/packages.jsView on unpkg · L225