AI Coding Agent
Launching the agent enables command hooks that report matched Git push metadata to a private host. The report includes repository identity, branch, commit hashes, review URL, and an account identifier.
Package source references child process execution.
scripts/postinstall.jsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage source references weak cryptographic algorithms.
comate-engine/node_modules/win-ca/lib/hash.jsView on unpkg · L8A single source file combines environment access, network access, and code or shell execution with blocking evidence.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source appears to collect browser login credentials for exfiltration.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bundle/index.jsSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1Package ships native binary artifacts.
comate-engine/node_modules/sqlite-vec-darwin-arm64/vec0.dylibView on unpkgPackage ships WebAssembly modules.
comate-engine/node_modules/tree-sitter-bash/tree-sitter-bash.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_source_text_guard.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-host/dist/user-CAYijOXi.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-shared-internals/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/preview-proxy/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/adapter-chrome/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-host/dist/main.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/assets/skills/baidu-cloud-bos/scripts/bos_node.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/web-tree-sitter/lib/tree-sitter.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/web-tree-sitter/tree-sitter.cjsView on unpkgThis report applies to @comate/zulu@1.7.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source exposes local file and command tools to a remote model endpoint.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source appears to collect browser login credentials for exfiltration.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bundle/index.jsSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1Package ships native binary artifacts.
comate-engine/node_modules/sqlite-vec-darwin-arm64/vec0.dylibView on unpkgPackage ships WebAssembly modules.
comate-engine/node_modules/tree-sitter-bash/tree-sitter-bash.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_source_text_guard.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-host/dist/user-CAYijOXi.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-shared-internals/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/preview-proxy/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/adapter-chrome/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-host/dist/main.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/assets/skills/baidu-cloud-bos/scripts/bos_node.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/web-tree-sitter/lib/tree-sitter.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/web-tree-sitter/tree-sitter.cjsView on unpkgPackage source references weak cryptographic algorithms.
comate-engine/node_modules/win-ca/lib/hash.jsView on unpkg · L8Source downloads or fetches remote code and executes it.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source exposes local file and command tools to a remote model endpoint.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@comate/plugin-engine/dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
comate-engine/node_modules/@baidu/comate-browser-use/dist/launch-chrome/index.jsView on unpkg