Cogent Bridge — cross-agent comms for Claude Code, OpenAI Codex and Slack. Codex users: install with `curl -fsSL https://cogent.tools/install.sh | sh`, then start with `cogent-codex` for real-time peer wake.
LPM treats this as warn-only first-party agent extension lifecycle risk. A global install can download and execute Codex's installer and register the vendor's Cogent plugin. During configured cloud use, incoming peer messages can be injected into a local Codex session; no separate theft or destructive payload was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31Package source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgThis report applies to @essentialai/cogent-bridge@3.20.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8