Helios self-improvement lab
npm postinstall deploys an opaque bundled native binding into a dependency-owned runtime path. Source does not establish malicious native behavior, but the binary will be used by the dependency at runtime.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
extensions/helios-governance/lib/crawl4ai-client.tsView on unpkg · L884Package source references a known benign dynamic code generation pattern.
lib/graph/erd/parse-erd.jsView on unpkg · L244Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/memgraph-broker-launcher.tsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
extensions/memgraph-autostart.tsView on unpkg · L12Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
extensions/memgraph-autostart.tsView on unpkg · L12Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L713Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/types.tsView on unpkg · L949Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/helios-rpc.cjsView on unpkgThis report applies to @cgh567/agent@2.6.23.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L12A single source file combines environment access, network access, and code or shell execution; review context before blocking.
extensions/memgraph-autostart.tsView on unpkg · L12Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
extensions/memgraph-autostart.tsView on unpkg · L12Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L713Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/types.tsView on unpkg · L949Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/helios-rpc.cjsView on unpkgPackage contains a possible secret pattern.
extensions/helios-governance/lib/crawl4ai-client.tsView on unpkg · L884Package source references a known benign dynamic code generation pattern.
lib/graph/erd/parse-erd.jsView on unpkg · L244Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/memgraph-broker-launcher.tsView on unpkg · L3