Multi-Agent Swarm Orchestration, Empirical Dialectics & Ceremonies on top of Rhizo & Vine
No attack was identified. The launcher obtains a platform binary from the package’s own GitHub releases and runs it when the user invokes the CLI.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4bin/run.js selects a release binary from the package’s GitHub repository, then runs it with the user’s arguments and environment when the CLI is invoked.
bin/run.jsView on unpkg · L86bin/run.js selects a release binary from the package’s GitHub repository, then runs it with the user’s arguments and environment when the CLI is invoked.
bin/run.jsView on unpkg · L146Package ships non-JavaScript build or shell helper files.
scripts/launch_tmux_swarm.shView on unpkgpackage.json routes both the package entrypoint and the garden command to bin/run.js; no lifecycle hooks are declared.
package.jsonView on unpkg · L5package.json routes both the package entrypoint and the garden command to bin/run.js; no lifecycle hooks are declared.
package.jsonView on unpkg · L2This report applies to @axiomantic/garden@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
scripts/launch_tmux_swarm.shView on unpkgbin/run.js selects a release binary from the package’s GitHub repository, then runs it with the user’s arguments and environment when the CLI is invoked.
bin/run.jsView on unpkg · L86bin/run.js selects a release binary from the package’s GitHub repository, then runs it with the user’s arguments and environment when the CLI is invoked.
bin/run.jsView on unpkg · L146package.json routes both the package entrypoint and the garden command to bin/run.js; no lifecycle hooks are declared.
package.jsonView on unpkg · L2package.json routes both the package entrypoint and the garden command to bin/run.js; no lifecycle hooks are declared.
package.jsonView on unpkg · L5