Loading npm security reports…
ContinueVault CLI agent — stores Claude Code and Codex sessions
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Source writes installer persistence such as shell profile or service configuration.
dist/daemon/service.jsView on unpkg · L10Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/codex-mcp-auth.jsView on unpkg · L2Source writes installer persistence such as shell profile or service configuration.
dist/daemon/service.jsView on unpkg · L10Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/codex-mcp-auth.jsView on unpkg · L2