Inter-assistant communication bus, monotonic fencing locks, and work queues over Redis
No attack was identified in the inspected JavaScript launcher. It selects a platform binary, downloads it from the package's GitHub release when needed, and runs it as the requested command.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4bin/run.js fetches a platform-specific binary from the package's GitHub release and runs it with the caller's arguments.
bin/run.jsView on unpkg · L91bin/run.js fetches a platform-specific binary from the package's GitHub release and runs it with the caller's arguments.
bin/run.jsView on unpkg · L140Package ships native binary artifacts.
bin/binaries/rhizo-darwin-arm64View on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/ci/build.shView on unpkgpackage.json identifies the package as a Redis-based inter-assistant communication tool and points its entrypoint to the launcher.
package.jsonView on unpkg · L2This report applies to @axiomantic/rhizo@0.2.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L4Package ships native binary artifacts.
bin/binaries/rhizo-darwin-arm64View on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/ci/build.shView on unpkgpackage.json identifies the package as a Redis-based inter-assistant communication tool and points its entrypoint to the launcher.
package.jsonView on unpkg · L2bin/run.js fetches a platform-specific binary from the package's GitHub release and runs it with the caller's arguments.
bin/run.jsView on unpkg · L91bin/run.js fetches a platform-specific binary from the package's GitHub release and runs it with the caller's arguments.
bin/run.jsView on unpkg · L140