Apex Copilot CLI — AI advisor for Web3 founders
Running apex fetches opaque executables and runs the main downloaded binary. Download integrity is not verified and redirects are unrestricted.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L72Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgThe command downloads a release binary without a checksum or signature check.
apex.cjsView on unpkg · L45The downloader follows redirect locations without restricting the destination host.
apex.cjsView on unpkg · L30A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to @apexacc/cli@1.5.109.
See version security history for other recorded verdicts.
Evidence last updated: .
The downloader follows redirect locations without restricting the destination host.
apex.cjsView on unpkg · L30The command downloads a release binary without a checksum or signature check.
apex.cjsView on unpkg · L45Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L72This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg