lunR — terminal coding agent CLI with read, bash, edit, write tools and session management
No confirmed attack surface was established from the install hook or the indicated MCP configuration module. The install hook only launches a local Chromium installer, and agent config writes identified in source stay on the package's own .lunr path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Package source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-DSIKTUPW.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-DSIKTUPW.jsView on unpkg · L2330Package source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-HFVZUPFJ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgThis report applies to @ashx-j/lunr@0.2.24.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-HFVZUPFJ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgPackage source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Package source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-DSIKTUPW.jsView on unpkg · L2330Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-DSIKTUPW.jsView on unpkgPackage source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7