Cogent Bridge — cross-agent comms for Claude Code, OpenAI Codex and Slack. Codex users: install with `curl -fsSL https://cogent.tools/install.sh | sh`, then start with `cogent-codex` for real-time peer wake.
LPM treats this as warn-only first-party agent extension lifecycle risk. A global npm install automatically installs a managed Codex build and registers a Cogent plugin in Codex. No credential theft or destructive behavior was identified in the inspected source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31Package source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/auto-relay.jsView on unpkgThis report applies to @essentialai/cogent-bridge@3.25.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/npm-update-check.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-app-server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-preflight.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-global.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/cc-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/codex-cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend/npm-update-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/auto-relay.jsView on unpkgPackage source references child process execution.
dist/bin/cogent-codex.jsView on unpkg · L31Source downloads or fetches remote code and executes it.
dist/bin/cogent-codex.jsView on unpkg · L31A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/cogent-codex.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/cogent-codex.jsView on unpkg