lunR — terminal coding agent CLI with read, bash, edit, write tools and session management
At runtime, the package reads a Grok CLI OAuth credential, transmits its access token to a fixed endpoint, and may update the external Grok credential file. This is a cross-application credential bridge rather than ordinary package-local authentication.
Package contains a possible secret pattern.
dist/node-runtime/chunk-WJVFOIB5.jsView on unpkg · L20396Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-UWQYRSYQ.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-UWQYRSYQ.jsView on unpkg · L2330Package source references dynamic require/import behavior.
dist/core/extensions/loader.jsView on unpkg · L21Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/node-runtime/chunk-2BUAYZ7K.jsView on unpkgThis report applies to @ashx-j/lunr@0.2.21.
See version security history for other recorded verdicts.
Evidence last updated: .
Package contains a possible secret pattern.
dist/node-runtime/chunk-WJVFOIB5.jsView on unpkg · L20396Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/node-runtime/chunk-2BUAYZ7K.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-UWQYRSYQ.jsView on unpkg · L2330Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-UWQYRSYQ.jsView on unpkgPackage source references dynamic require/import behavior.
dist/core/extensions/loader.jsView on unpkg · L21Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7