Multi-agent gateway for Claude
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/discord/receiver.jsView on unpkgPackage source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/api/router.jsView on unpkg · L447Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cron/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/gateway-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/agent-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/installer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/telegram/receiver.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/reviewer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/line-webhook-router.jsView on unpkgThis report applies to @0xmaxma/claude-gateway@1.8.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L32Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cron/manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/gateway-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/agent-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/installer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/telegram/receiver.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/skill-learning/reviewer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/line-webhook-router.jsView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/discord/receiver.jsView on unpkgPackage source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/api/router.jsView on unpkg · L447Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkg