Jait AI gateway — local-first AI coding agent with terminal, filesystem, and browser control
Installing the npm package automatically provisions a Python runtime and downloads an external package through pip. This introduces unconsented third-party code execution during npm installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
web-dist/assets/index-wUWsnhHq.jsView on unpkg · L141Manifest entrypoint contains risky behavior absent from dist/build output.
bin/jait.mjsView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/jait.mjsView on unpkgPackage source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
bin/install-runtime.mjsView on unpkg · L20A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L104Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tools/browser-tools.jsView on unpkg · L5Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/surfaces/browser.jsView on unpkg · L398Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/browser.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/services/git-forge.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/git-forge.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels/manager.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/security/sandbox-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/project.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/live-view-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/maintenance.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/channels/msteams/connector.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/channels/telegram/connector.jsView on unpkgThis report applies to @jait/gateway@0.1.848.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L24Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/surfaces/browser.jsView on unpkg · L398Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/browser.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/services/git-forge.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/git-forge.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
web-dist/noVNC/app/images/icons/MakefileView on unpkgPackage ships high-entropy non-source blobs.
web-dist/noVNC/app/sounds/bell.ogaView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/channels/manager.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/surfaces/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/security/sandbox-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/project.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/live-view-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/maintenance.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/channels/msteams/connector.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/channels/telegram/connector.jsView on unpkgPackage source references child process execution.
web-dist/assets/index-wUWsnhHq.jsView on unpkg · L141Manifest entrypoint contains risky behavior absent from dist/build output.
bin/jait.mjsView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/jait.mjsView on unpkgPackage source references dynamic code evaluation.
dist/tools/screenshot-tools.jsView on unpkg · L59Package source references dynamic require/import behavior.
bin/install-runtime.mjsView on unpkg · L20A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/tools/redeploy-tools.jsView on unpkg · L104Package source invokes a package manager install command at runtime.
dist/tools/redeploy-tools.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
dist/tools/browser-tools.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tools/browser-tools.jsView on unpkg · L5