Jait AI gateway — local-first AI coding agent with terminal, filesystem, and browser control
npm postinstall provisions a Python virtual environment and downloads a fixed Graphify package. This is unconsented install-time third-party code acquisition, but the reviewed JavaScript contains no confirmed payload or exfiltration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
web-dist/assets/php-Csjmro_R.jsView on unpkg · L1Package source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
web-dist/assets/codeql-DsOJ9woJ.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L101Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
web-dist/assets/index-2K7jP91E.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
web-dist/assets/flowDiagram-UKHOOZJN-BzI6GKJQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
web-dist/assets/ganttDiagram-PKOTCBZU-BZLe_WOw.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
web-dist/assets/wardleyDiagram-T6FBY63Y-iVGntqw1.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L24Package ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
web-dist/assets/index-2K7jP91E.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
web-dist/assets/flowDiagram-UKHOOZJN-BzI6GKJQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
web-dist/assets/ganttDiagram-PKOTCBZU-BZLe_WOw.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
web-dist/assets/wardleyDiagram-T6FBY63Y-iVGntqw1.jsView on unpkgPackage source references child process execution.
web-dist/assets/php-Csjmro_R.jsView on unpkg · L1Package source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
web-dist/assets/codeql-DsOJ9woJ.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L101Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L4