APX — unified CLI + daemon for the Agent Project Context (APC) standard.
LPM flags this version as an AI-agent control-surface risk. npm postinstall retrieves remote skill content and writes it to global directories consumed by multiple AI-agent tools. This is an unconsented broad AI-agent control-surface mutation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/routines/runner.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L401Package source references dynamic require/import behavior.
src/interfaces/web/dist/assets/index-DUXlrW8P.jsView on unpkg · L59Source writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7Package ships non-JavaScript build or shell helper files.
src/host/daemon/whisper-server.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/admin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/tui/context/sdk-apx.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Package source references dynamic require/import behavior.
src/interfaces/web/dist/assets/index-DUXlrW8P.jsView on unpkg · L59Package ships non-JavaScript build or shell helper files.
src/host/daemon/whisper-server.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/api/admin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/interfaces/tui/context/sdk-apx.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/routines/runner.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L401Source writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7