•matchType = previous_version_dangerous_delta
matchedPackage = @guangnao/agent-proxy@1.2.4
matchedIdentity = npm:QGd1YW5nbmFvL2FnZW50LXByb3h5:1.2.4
similarity = 0.500
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkg 1#!/usr/bin/env node
L2: import{createInterface as Qc}from"node:readline/promises";import{spawnSync as Ge}from"node:child_process";import{stdin as Lo,stdout as jo}from"node:process";var Fn="1.0.1";var Te=(...
L3: `)}var Z={info:(e,t)=>Ft(process.stdout,"info",e,t),warn:(e,t)=>Ft(process.stderr,"warn",e,t),error:(e,t)=>Ft(process.stderr,"error",e,t)};var lt=class{constructor(t,n){this.max=t;...
HighChild Process
Package source references child process execution.
dist/cli.jsView on unpkg · L1 23L24: `),u=(w,C={})=>({id:o,object:"response",created_at:c,status:w,model:t.model,error:null,...C}),y=async()=>{n.started()||await a("response.created",{response:u("in_progress",{output:...
L25: Note Auth flows open a browser. No browser on this box?
...
L35:
L36: `,zs=e=>e.startsWith("~")?nn(wr(),e.slice(1)):e,xt=()=>process.env.CODEX_HOME||nn(wr(),".codex"),se=()=>process.env.CODEX_AUTH_FILE||nn(xt(),"auth.json"),kr=(e,t)=>{process.platfor...
L37:
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L23 20L21: `),messages:c,stream:t.stream===!0,maxTokens:typeof t.max_output_tokens=="number"?t.max_output_tokens:void 0}}function cr(e){return{input_tokens:e.usage.inputTokens,output_tokens:e...
L22: data: ${JSON.stringify({type:w,sequence_number:d++,...C})}
L23:
L24: `),u=(w,C={})=>({id:o,object:"response",created_at:c,status:w,model:t.model,error:null,...C}),y=async()=>{n.started()||await a("response.created",{response:u("in_progress",{output:...
L25: Note Auth flows open a browser. No browser on this box?
...
L35:
L36: `,zs=e=>e.startsWith("~")?nn(wr(),e.slice(1)):e,xt=()=>process.env.CODEX_HOME||nn(wr(),".codex"),se=()=>process.env.CODEX_AUTH_FILE||nn(xt(),"auth.json"),kr=(e,t)=>{process.platfor...
L37:
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L20 1#!/usr/bin/env node
L2: import{createInterface as Qc}from"node:readline/promises";import{spawnSync as Ge}from"node:child_process";import{stdin as Lo,stdout as jo}from"node:process";var Fn="1.0.1";var Te=(...
L3: `)}var Z={info:(e,t)=>Ft(process.stdout,"info",e,t),warn:(e,t)=>Ft(process.stderr,"warn",e,t),error:(e,t)=>Ft(process.stderr,"error",e,t)};var lt=class{constructor(t,n){this.max=t;...
L4:
L5: `)}function ue(){let e={text:"",thinking:"",usage:Jn(),stop:"stop"};return{sink:{meta(n){n.id&&(e.id=n.id),n.model&&(e.model=n.model)},text(n){e.text+=n},thinking(n){e.thinking+=n}...
L6: `}let d=ft(n.maxConcurrency,!!n.claudeToken),i=await d.acquire();try{await ht({bin:n.claudeBin,args:o,prompt:s,cwd:i.workDir,env:{...process.env,HOME:i.home,CLAUDE_CONFIG_DIR:i.con...
...
L23:
L24: `),u
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L1 4L5: `)}function ue(){let e={text:"",thinking:"",usage:Jn(),stop:"stop"};return{sink:{meta(n){n.id&&(e.id=n.id),n.model&&(e.model=n.model)},text(n){e.text+=n},thinking(n){e.thinking+=n}...
L6: `}let d=ft(n.maxConcurrency,!!n.claudeToken),i=await d.acquire();try{await ht({bin:n.claudeBin,args:o,prompt:s,cwd:i.workDir,env:{...process.env,HOME:i.home,CLAUDE_CONFIG_DIR:i.con...
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L4