Apex Copilot CLI — AI advisor for Web3 founders
Running apex fetches an opaque platform binary, makes it executable, and launches it. The fetched payload is not integrity-verified and redirect destinations are unrestricted.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L72Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1The CLI downloads an executable from GitHub when a user runs it.
apex.cjsView on unpkg · L45The download follows redirect targets without restricting the destination host or verifying a checksum or signature.
apex.cjsView on unpkg · L30It marks the downloaded file executable and runs it with the caller's arguments and environment.
apex.cjsView on unpkg · L53A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to @apexacc/cli@1.5.108.
See version security history for other recorded verdicts.
Evidence last updated: .
The download follows redirect targets without restricting the destination host or verifying a checksum or signature.
apex.cjsView on unpkg · L30The CLI downloads an executable from GitHub when a user runs it.
apex.cjsView on unpkg · L45It marks the downloaded file executable and runs it with the caller's arguments and environment.
apex.cjsView on unpkg · L53Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L72A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg