Apex Copilot CLI — AI advisor for Web3 founders
Running the apex command on Windows attempts to weaken a system application-control policy. It then downloads and executes unauthenticated remote binaries while passing through the caller's environment.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L81A manifest entrypoint or package-local install chain reaches persistence behavior.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
apex.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to @apexacc/cli@1.5.120.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches persistence behavior.
apex.cjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L81