Self-judging agent orchestration layer for OpenCode. Reads memory, scores sessions, dispatches decisions.
LPM flags this version as an AI-agent control-surface risk. On npm install, postinstall writes binding agent instructions into the user OpenCode config and rewrites opencode.jsonc so those instructions load. The only skip is an environment variable set before install.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
dist/lib.jsView on unpkg · L4Package source references a known benign dynamic code generation pattern.
dist/lib.jsView on unpkg · L169A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/mcp-server.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp-server.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/bootstrap-agents-md.mjsView on unpkg · L8Package ships high-entropy non-source blobs.
dist/skills/chore.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/skills/chore.tar.gzView on unpkgThis report applies to @herjarsa/omo-meta-governor@0.50.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/mcp-server.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/mcp-server.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mcp-server.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L55Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L55A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/mcp-server.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp-server.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/bootstrap-agents-md.mjsView on unpkg · L8Package ships high-entropy non-source blobs.
dist/skills/chore.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/skills/chore.tar.gzView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/lib.jsView on unpkg · L169Package source invokes a package manager install command at runtime.
dist/lib.jsView on unpkg · L4Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/mcp-server.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/mcp-server.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mcp-server.jsView on unpkg