CodeVine AI CLI — setup, sync, and manage your Claude Code environment
LPM treats this as warn-only first-party agent extension lifecycle risk. No confirmed malicious install-time behavior was found. Runtime has a risky obfuscated self-updating CLI that can execute cached CodeVine code and user-invoked AI client setup/upload features.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.cjsView on unpkg · L94Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/cli.cjsView on unpkg · L94Package source references dynamic require/import behavior.
dist/cli.cjsView on unpkg · L13Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L20Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Package source references dynamic require/import behavior.
dist/cli.cjsView on unpkg · L13A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.cjsView on unpkg · L94Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/cli.cjsView on unpkg · L94