Apex Copilot CLI — AI advisor for Web3 founders
Running the apex command can fetch and execute an opaque remote binary. The source provides no integrity verification for that binary.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L90Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgThe CLI downloads a versioned executable from GitHub without a checksum or signature check, then marks it executable.
apex.cjsView on unpkg · L48The downloaded executable is run with the caller's complete environment.
apex.cjsView on unpkg · L99A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to @apexacc/cli@1.5.86.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes bytes from a remote response into a privileged operating-system path.
apex.cjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
apex.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe CLI downloads a versioned executable from GitHub without a checksum or signature check, then marks it executable.
apex.cjsView on unpkg · L48A single source file combines environment access, network access, and code or shell execution; review context before blocking.
apex.cjsView on unpkg · L90The downloaded executable is run with the caller's complete environment.
apex.cjsView on unpkg · L99