AI Coding Agent
No confirmed malicious attack surface. The CLI can fetch optional skills only through an explicit user command and stores them in its own Comate directory.
Package source references child process execution.
scripts/postinstall.jsView on unpkg · L13A single source file combines environment access, network access, and code or shell execution; review context before blocking.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkg · L5Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/bundle/index.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bundle/index.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bundle/index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/bundle/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bundle/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bundle/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_language_detector.pyView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L13Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/bundle/index.jsView on unpkg · L32A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bundle/index.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
comate-engine/assets/skills/icode/scripts/common.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
comate-engine/assets/skills/build-swe-data-auto/tests/test_language_detector.pyView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
comate-engine/assets/hooks/local-swe-task-reporter.jsView on unpkg · L5This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bundle/index.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bundle/index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/bundle/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle/index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bundle/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bundle/index.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bundle/index.jsView on unpkg