Jait AI gateway — local-first AI coding agent with terminal, filesystem, and browser control
Installation automatically fetches and installs an external Python runtime. This executes package-manager-controlled third-party code before the user runs the Jait command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
web-dist/assets/index-Bdydn-FB.jsView on unpkg · L141Manifest entrypoint contains risky behavior absent from dist/build output.
bin/jait.mjsView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/jait.mjsView on unpkgPackage source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
web-dist/assets/codeql-DsOJ9woJ.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L101Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tools/browser-tools.jsView on unpkg · L5Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/surfaces/browser.jsView on unpkg · L398A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/services/git-forge.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels/manager.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/network.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/providers/acp-binary-launcher.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/providers/acp-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/primary-link.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/os-control/windows-driver.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/security/sandbox-manager.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L24Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/surfaces/browser.jsView on unpkg · L398A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/services/git-forge.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels/manager.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/network.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/providers/acp-binary-launcher.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/providers/acp-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/primary-link.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/os-control/windows-driver.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/security/sandbox-manager.jsView on unpkgPackage source references child process execution.
web-dist/assets/index-Bdydn-FB.jsView on unpkg · L141Manifest entrypoint contains risky behavior absent from dist/build output.
bin/jait.mjsView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/jait.mjsView on unpkgPackage source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
web-dist/assets/codeql-DsOJ9woJ.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L101Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tools/browser-tools.jsView on unpkg · L5