lunR — terminal coding agent CLI with read, bash, edit, write tools and session management
No confirmed attack surface was established. The install hook only attempts a Playwright Chromium download, and MCP config handling is part of the coding-agent runtime rather than an unconsented install mutation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Package source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Package source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-LWJXTA6Z.jsView on unpkg · L2280Package source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-4SBQAI4T.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-E75WFZ33.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgThis report applies to @ashx-j/lunr@0.2.26.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L35Package contains a possible secret pattern.
dist/node-runtime/chunk-UQUCFAJ3.jsView on unpkg · L20396Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/node-runtime/chunk-4SBQAI4T.jsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/node-runtime/pi-prompt-template-model-QWTCGLJU.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/builtin-extensions/pi-lsp-extension/src/tree-sitter/pattern-compiler.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-CSFI6YXL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-FQMM2EZ2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/lsp-manager-3ASUSO4T.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-intercom/broker/spawn.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-Q4Q6D4IY.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/shell.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/builtin-extensions/pi-web-access/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/footer-data-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/extension-editor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-E75WFZ33.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/chunk-XTHQ7XR7.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/node-runtime/github-extract-F64RZOEA.jsView on unpkgPackage source references shell execution.
dist/builtin-extensions/pi-subagents/src/runs/shared/acceptance.jsView on unpkg · L994Package source references a known benign dynamic code generation pattern.
dist/node-runtime/chunk-LWJXTA6Z.jsView on unpkg · L2280Package source references dynamic require/import behavior.
dist/modes/interactive/theme/theme.jsView on unpkg · L11Package source references weak cryptographic algorithms.
dist/core/rollback.jsView on unpkg · L27Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7