AI Coding Agent
No confirmed malicious attack surface. Network, subprocess, and update functionality are CLI runtime features rather than install-time execution.
Package source references child process execution.
scripts/postinstall.jsView on unpkg · L13A single source file combines environment access, network access, and code or shell execution; review context before blocking.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkg · L5Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/bundle/index.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bundle/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bundle/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bundle/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_language_detector.pyView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L13Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/bundle/index.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_language_detector.pyView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkg · L5This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bundle/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bundle/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bundle/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkg