Multi-agent gateway for Claude
Inspected source did not establish a confirmed attack. The postinstall hook only installs dependencies under the package mcp directory, and the sampled agent routes write a fixed set of workspace markdown files.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Package source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/orchestration/audit-codex-context.cjsView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/orchestration/telegram-tool-status.jsView on unpkg · L104Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/orchestration/container.jsView on unpkg · L13Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/compose-generator.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/api/router.jsView on unpkgThis report applies to @0xmaxma/claude-gateway@2.0.9.
See version security history for other recorded verdicts.
Evidence last updated: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L33Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Package source references child process execution.
dist/discord/receiver.jsView on unpkg · L36Package source references dynamic require/import behavior.
dist/webhook/manager.jsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/orchestration/audit-codex-context.cjsView on unpkg · L7Source reaches cloud instance metadata or link-local credential endpoints.
dist/connectors/mcp-oauth.js#virtual:normalized:round1View on unpkg · L4Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/orchestration/container.jsView on unpkg · L13Package source invokes a package manager install command at runtime.
dist/packages/registry.jsView on unpkg · L188Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/packages/registry.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/agent/dreaming/migrate.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/socket-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/commands/gateway.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/compactor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api/skills-router.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/compose-generator.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/api/router.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/orchestration/telegram-tool-status.jsView on unpkg · L104A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/orchestration/telegram-tool-status.jsView on unpkg · L104