Elyntic self-improvement lab
Loading this package as a Pi extension starts an updater on session start. For a non-git agent directory it downloads helios-agent-latest.tar.gz from the Elyntic GitHub release host, extracts it, and replaces that agent directory, then runs pi update. Checksum failure does not stop the install.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/elyntic-ollama-models.cjsView on unpkg · L23Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/design-elevation/index.tsView on unpkg · L21A single source file combines environment access, network access, and code or shell execution; review context before blocking.
daemon/lib/wizard-engine.js#virtual:normalized:round1View on unpkg · L326Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
daemon/lib/wizard-engine.js#virtual:normalized:round1View on unpkg · L326Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L715A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
backfill-dashboard.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/mental-model/metadata-recompute.tsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
daemon/daemon-manager.jsView on unpkg · L21Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/auto-update.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
daemon/lib/task-history-store.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/atlas-integration.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/btw-sidebar.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/triage-core/desktop-authority.jsView on unpkgThis report applies to @cgh567/agent@2.6.43.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L14A single source file combines environment access, network access, and code or shell execution; review context before blocking.
daemon/lib/wizard-engine.js#virtual:normalized:round1View on unpkg · L326Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
daemon/lib/wizard-engine.js#virtual:normalized:round1View on unpkg · L326Source silently spawns a Node process to execute an inline dependency payload.
backfill-dashboard.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
backfill-dashboard.jsView on unpkg · L715A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
backfill-dashboard.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
lib/triage-core/mental-model/metadata-recompute.tsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
daemon/daemon-manager.jsView on unpkg · L21Package ships non-JavaScript build or shell helper files.
run-backfill.ps1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/auto-update.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
daemon/lib/task-history-store.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/atlas-integration.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/btw-sidebar.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/triage-core/desktop-authority.jsView on unpkgPackage source references child process execution.
bin/elyntic-ollama-models.cjsView on unpkg · L23Package source references dynamic require/import behavior.
brainv2/task-context-strategy.tsView on unpkg · L35Package source references weak cryptographic algorithms.
extensions/design-elevation/index.tsView on unpkg · L21