APX — unified CLI + daemon for the Agent Project Context (APC) standard.
LPM flags this version as an AI-agent control-surface risk. Npm postinstall fetches a remotely controlled skill and installs package skills into several global AI-agent control directories. This changes agent instructions without an explicit setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/net/tailscale.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L730Package source references dynamic require/import behavior.
src/core/voice/transcription.js#virtual:normalized:round1View on unpkg · L52Package source references weak cryptographic algorithms.
src/core/channels/whatsapp/stickers.jsView on unpkg · L36A manifest entrypoint or package-local install chain reaches persistence behavior.
src/core/desktop/autostart.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/autostart.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/interfaces/cli/http.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/http.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
src/host/daemon/pty-bridge.pyView on unpkgPackage ships compressed or archive-like blobs.
src/interfaces/web/dist/sw.js.gzView on unpkgPackage ships high-entropy non-source blobs.
src/interfaces/web/dist/assets/index-5Bx5Ls6c.js.brView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
src/interfaces/android/gradle/wrapper/gradle-wrapper.jarView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/core/http-tools/browser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/image.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/admin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/desktop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/voice.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/routines/runner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/deck-exec.jsView on unpkgThis report applies to @agentprojectcontext/apx@1.104.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L48Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L48Package source references dynamic require/import behavior.
src/core/voice/transcription.js#virtual:normalized:round1View on unpkg · L52A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/interfaces/cli/http.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/http.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
src/host/daemon/pty-bridge.pyView on unpkgPackage ships compressed or archive-like blobs.
src/interfaces/web/dist/sw.js.gzView on unpkgPackage ships high-entropy non-source blobs.
src/interfaces/web/dist/assets/index-5Bx5Ls6c.js.brView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
src/interfaces/android/gradle/wrapper/gradle-wrapper.jarView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/core/http-tools/browser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/image.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/admin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/desktop.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/cli/commands/voice.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/routines/runner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/deck-exec.jsView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/net/tailscale.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L730Package source references weak cryptographic algorithms.
src/core/channels/whatsapp/stickers.jsView on unpkg · L36Source writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
src/core/desktop/autostart.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/autostart.jsView on unpkg