Jarela — local chat interface for LangGraph agents (multi-provider, single-process, SQLite-backed).
Two runtime API routes have no visible route-level access control. If the server is deliberately bound beyond loopback, a network client can read text files or trigger a global self-update.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
app/api/v1/update/apply/route.tsView on unpkg · L19Package source references dynamic code evaluation.
.next/standalone/node_modules/next/dist/compiled/browserslist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
browser-extension/agent-overlay.jsView on unpkg · L57Package source references weak cryptographic algorithms.
lib/embeddings/index.tsView on unpkg · L51A manifest entrypoint or package-local install chain reaches persistence behavior.
scripts/service-install.mjsView on unpkg · L18Source writes installer persistence such as shell profile or service configuration.
scripts/service-install.mjsView on unpkg · L18A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/update.mjsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/update.mjsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
lib/health/probes.tsView on unpkg · L12Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
.next/standalone/node_modules/next/dist/compiled/@vercel/nft/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
.next/standalone/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source passes code obtained from a remote response into a dynamic execution sink.
.next/standalone/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Package ships native binary artifacts.
.next/standalone/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.18.6View on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/installed-launcher.ps1View on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.next/standalone/.next/server/chunks/5210.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
.next/standalone/.next/server/chunks/5210.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
.next/standalone/node_modules/@keyv/serialize/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.next/standalone/node_modules/@langchain/core/dist/utils/async_caller.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.next/standalone/node_modules/@langchain/core/dist/utils/async_caller.jsView on unpkgThis report applies to @circuitwall/jarela@1.41.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L96Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
lib/health/probes.tsView on unpkg · L12Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
.next/standalone/node_modules/next/dist/compiled/@vercel/nft/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
.next/standalone/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source passes code obtained from a remote response into a dynamic execution sink.
.next/standalone/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Package ships native binary artifacts.
.next/standalone/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.18.6View on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/installed-launcher.ps1View on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.next/standalone/.next/server/chunks/5210.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
.next/standalone/.next/server/chunks/5210.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
.next/standalone/node_modules/@keyv/serialize/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.next/standalone/node_modules/@langchain/core/dist/utils/async_caller.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
.next/standalone/node_modules/@langchain/core/dist/utils/async_caller.jsView on unpkgPackage source references child process execution.
app/api/v1/update/apply/route.tsView on unpkg · L19Package source references dynamic code evaluation.
.next/standalone/node_modules/next/dist/compiled/browserslist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
browser-extension/agent-overlay.jsView on unpkg · L57Package source references weak cryptographic algorithms.
lib/embeddings/index.tsView on unpkg · L51Source writes installer persistence such as shell profile or service configuration.
scripts/service-install.mjsView on unpkg · L18A manifest entrypoint or package-local install chain reaches persistence behavior.
scripts/service-install.mjsView on unpkg · L18A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/update.mjsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/update.mjsView on unpkg