APX — unified CLI + daemon for the Agent Project Context (APC) standard.
LPM flags this version as an AI-agent control-surface risk. Automatic installation changes global AI-agent skill directories and can obtain installed skill content remotely. This is an unconsented broad AI-agent control-surface mutation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L730Package source references dynamic require/import behavior.
src/core/voice/transcription.js#virtual:normalized:round1View on unpkg · L52Package source references weak cryptographic algorithms.
src/core/channels/whatsapp/stickers.jsView on unpkg · L36A manifest entrypoint or package-local install chain reaches persistence behavior.
src/core/desktop/autostart.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/autostart.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/interfaces/cli/http.jsView on unpkg · L7Package ships non-JavaScript build or shell helper files.
src/host/daemon/pty-bridge.pyView on unpkgPackage ships compressed or archive-like blobs.
src/interfaces/web/dist/sw.js.gzView on unpkgPackage ships high-entropy non-source blobs.
src/interfaces/web/dist/assets/index-BhXHey_a.js.map.gzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
src/interfaces/android/gradle/wrapper/gradle-wrapper.jarView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/core/http-tools/browser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/deck-exec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/http-tools/search.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/mcp/runner.jsView on unpkgThis report applies to @agentprojectcontext/apx@1.94.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
src/core/artifacts/tunnel.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
src/core/artifacts/tunnel.jsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
src/core/http-tools/browser.jsView on unpkg · L730Package source references dynamic require/import behavior.
src/core/voice/transcription.js#virtual:normalized:round1View on unpkg · L52Package source references weak cryptographic algorithms.
src/core/channels/whatsapp/stickers.jsView on unpkg · L36A manifest entrypoint or package-local install chain reaches persistence behavior.
src/core/desktop/autostart.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/autostart.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/interfaces/cli/http.jsView on unpkg · L7Package ships non-JavaScript build or shell helper files.
src/host/daemon/pty-bridge.pyView on unpkgPackage ships compressed or archive-like blobs.
src/interfaces/web/dist/sw.js.gzView on unpkgPackage ships high-entropy non-source blobs.
src/interfaces/web/dist/assets/index-BhXHey_a.js.map.gzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
src/interfaces/android/gradle/wrapper/gradle-wrapper.jarView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/core/http-tools/browser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/desktop/process.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/voice/engines/gemini.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/host/daemon/deck-exec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/http-tools/search.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/mcp/runner.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
src/core/desktop/autostart.jsView on unpkg · L7