Claudin — Claude Code opened to any LLM (OpenAI, Gemini, DeepSeek, Ollama, and 200+ models)
No confirmed malicious attack surface. Installation mutates only this package's launcher and adjacent vendor directory; runtime networking is package-aligned LLM/provider functionality.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/chunks/cli-1.1.20-y4b0v8se.mjsView on unpkg · L1Package source references child process execution.
dist/chunks/setup-1.1.20-rxx0xk5h.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L614Source appears to send environment or credential material to an external endpoint.
dist/chunks/cli-1.1.20-sx7811qs.mjsPackage source references weak cryptographic algorithms.
dist/chunks/hookChains-1.1.20-9xe50nmq.mjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.20-edmcts0d.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.20-rvn2axad.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.20-6dks41qc.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.20-6dks41qc.mjsView on unpkg · L1Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/chunks/defaultActionDeps-1.1.20-hwtzy20f.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.20-m90d7k90.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.20-1jxfjf9e.mjs
dist/chunks/openaiShim-1.1.20-1jxfjf9e.mjsView on unpkg · L11This report applies to @claudiolabs/claudin@1.1.20.
See version security history for other recorded verdicts.
Evidence last updated: .
Source exposes local file and command tools to a remote model endpoint.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L145A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L234Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L614Source appears to send environment or credential material to an external endpoint.
dist/chunks/cli-1.1.20-sx7811qs.mjsSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.20-rvn2axad.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.20-6dks41qc.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.20-6dks41qc.mjsView on unpkg · L1Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/chunks/defaultActionDeps-1.1.20-hwtzy20f.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.20-m90d7k90.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.20-1jxfjf9e.mjs
dist/chunks/openaiShim-1.1.20-1jxfjf9e.mjsView on unpkg · L11Package contains a possible secret pattern.
dist/chunks/cli-1.1.20-y4b0v8se.mjsView on unpkg · L1Package source references child process execution.
dist/chunks/setup-1.1.20-rxx0xk5h.mjsView on unpkg · L1Source exposes local file and command tools to a remote model endpoint.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L145A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/chunks/cli-1.1.20-sx7811qs.mjsView on unpkg · L234Package source references weak cryptographic algorithms.
dist/chunks/hookChains-1.1.20-9xe50nmq.mjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.20-edmcts0d.mjsView on unpkg · L1