Provider-agnostic AI coding agent for your terminal (binary distribution)
npm installation downloads an unpinned release archive, extracts it, and may execute its contained binary. The source contains no payload behavior to establish malicious intent, but this is unverified install-time remote code execution.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall runs install.js during npm installation.
package.jsonView on unpkg · L8Installer fetches a latest-release tarball with redirects and no integrity verification.
install.jsView on unpkg · L22Installer extracts the archive, clears macOS quarantine, and executes its binary when a bundled manifest exists.
install.jsView on unpkg · L39Repository source can be overridden through HIPMMCODE_REPO.
install.jsView on unpkg · L5This report applies to @hipmmai/hipmmcode@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9postinstall runs install.js during npm installation.
package.jsonView on unpkg · L8Repository source can be overridden through HIPMMCODE_REPO.
install.jsView on unpkg · L5Installer fetches a latest-release tarball with redirects and no integrity verification.
install.jsView on unpkg · L22Installer extracts the archive, clears macOS quarantine, and executes its binary when a bundled manifest exists.
install.jsView on unpkg · L39