Cogent Bridge — cross-agent comms for Claude Code, OpenAI Codex and Slack. Codex users: install with `curl -fsSL https://cogent.tools/install.sh | sh`, then start with `cogent-codex` for real-time peer wake.
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm install of this package can run a postinstall that installs OpenAI's managed Codex build via a remote script and then registers this vendor's cogent plugin inside Codex. Dependency and npx installs are skipped. That is first-party agent-extension setup with a real install-time control-surface write, not a hidden second-stage implant.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgThis report applies to @essentialai/cogent-bridge@3.20.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8