Cogent Bridge — cross-agent comms for Claude Code, OpenAI Codex and Slack. Codex users: install with `curl -fsSL https://cogent.tools/install.sh | sh`, then start with `cogent-codex` for real-time peer wake.
LPM flags this version as an AI-agent control-surface risk. On global npm installation, the postinstall script installs a managed Codex build and modifies Codex's plugin marketplace and installed plugins. These are unconsented changes to an external AI-agent control surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/startup.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgPackage source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L8