Wallet operations for AI agents and humans
LPM flags this version as an AI-agent control-surface risk. npm postinstall rewrites Claude Code, Cursor, and Windsurf instruction files in the home directory without asking. Those files then steer later agent sessions to this CLI for wallet and password actions.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource uses private key material to transfer cryptocurrency funds.
dist/cli.mjsView on unpkg · L56A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.mjsView on unpkg · L56Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.mjsView on unpkg · L52006A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L1Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.mjsView on unpkgThis report applies to @agentgates/cli@0.44.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L37Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L37Source uses private key material to transfer cryptocurrency funds.
dist/cli.mjsView on unpkg · L56A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.mjsView on unpkg · L56Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.mjsView on unpkg · L52006A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.mjsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.mjsView on unpkg