Kai Code Bridge runs Kai Code on your computer or server with your own coding subscriptions and local previews.
LPM treats this as warn-only first-party agent extension lifecycle risk. The package automatically modifies its bundled ACP dependency at installation and can create MCP extension configuration for Codex sessions. No confirmed malicious attack was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/preview.mjsView on unpkg · L8A manifest entrypoint or package-local install chain reaches persistence behavior.
src/service.mjsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/service.mjsView on unpkg · L4A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/preview.mjs#virtual:normalized:round1View on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
src/daemon.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/daemon.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/kai-bridge.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/models.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/selfupdate.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runner/tools/patch-claude-acp.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/companions.mjsView on unpkgThis report applies to @gleapai/kai-bridge@0.12.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L25A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/preview.mjs#virtual:normalized:round1View on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
src/daemon.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/kai-bridge.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/models.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/selfupdate.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
runner/tools/patch-claude-acp.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/companions.mjsView on unpkgPackage source references weak cryptographic algorithms.
src/preview.mjsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/service.mjsView on unpkg · L4A manifest entrypoint or package-local install chain reaches persistence behavior.
src/service.mjsView on unpkg · L4This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/daemon.mjsView on unpkg