lunR — terminal coding agent CLI with read, bash, edit, write tools and session management
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Package source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-YJMMG7C6.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-YJMMG7C6.jsView on unpkg · L2330Package source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-BX2RB477.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgThis report applies to @ashx-j/lunr@0.2.23.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-BX2RB477.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgPackage source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Package source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-YJMMG7C6.jsView on unpkg · L2330Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-YJMMG7C6.jsView on unpkgPackage source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7