Coding agent CLI with read, bash, edit, write tools and session management
Static analysis completed at 0.0% confidence. No malicious behavior was detected; 26 low-signal pattern(s) were surfaced and cleared.
Package source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L946Package source references a known benign dynamic code generation pattern.
examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references dynamic require/import behavior.
dist/utils/photon.jsView on unpkg · L17Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Package ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/resolve-config-value.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/tools-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-mode.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/clipboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-mcp-adapter/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/args.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/update-cli.jsView on unpkgThis report applies to @ashx-j/lunr@0.2.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Package ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/resolve-config-value.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/tools-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-mode.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/clipboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-mcp-adapter/utils.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/args.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/update-cli.jsView on unpkgPackage source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L946Package source references a known benign dynamic code generation pattern.
examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references dynamic require/import behavior.
dist/utils/photon.jsView on unpkg · L17Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7