Multi-agent gateway for Claude
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package automatically invokes Bun to install dependencies for its bundled MCP plugin. This is a first-party agent-extension setup action, but the inspected source does not establish credential theft or foreign agent-control mutation.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Package source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/orchestration/smoke-media.cjsView on unpkg · L31Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/orchestration/telegram-tool-status.jsView on unpkg · L104Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/orchestration/container.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/agent-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/installer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/compose-generator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/shell/pty-host.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp/tools/memory/archive-writer.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/orchestration/capabilities.jsView on unpkgThis report applies to @0xmaxma/claude-gateway@2.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Package source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/orchestration/smoke-media.cjsView on unpkg · L31Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/orchestration/telegram-tool-status.jsView on unpkg · L104Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/orchestration/container.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/agent-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/installer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/compose-generator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/shell/pty-host.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
mcp/tools/memory/archive-writer.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/orchestration/capabilities.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.