MaTrixOS — Agentic OS for OpenCode. Personalizable, communicating, self-improving, resilient.
LPM blocks this version under the AI-agent control-surface policy. npm postinstall mutates the user's global OpenCode agent-command surface. It installs package-controlled commands that OpenCode will discover at startup and invalidates related caches.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/oh-my-opencode.jsView on unpkg · L4Package source references dynamic require/import behavior.
bin/oh-my-opencode.jsView on unpkg · L16Source executes local commands and sends command output to an external endpoint.
dist/tui.jsView on unpkg · L681A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tui.jsView on unpkg · L681Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/skills/superpowers-brainstorming/scripts/server.cjsView on unpkgPackage source references weak cryptographic algorithms.
dist/cli/skills/superpowers-brainstorming/scripts/server.cjsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
postinstall.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/cli/skills/ast-grep/install.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
dist/cli/skills/ast-grep/tests/smoke.ps1View on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli-node/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli-node/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/matrixos.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/skills/superpowers-brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/lsp-daemon/dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/lsp-daemon/dist/client.jsView on unpkgSource contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/tui.jsView on unpkg · L681Source exposes local file and command tools to a remote model endpoint.
dist/tui.jsView on unpkg · L4518Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L95Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L95Package source references child process execution.
bin/oh-my-opencode.jsView on unpkg · L4Source executes local commands and sends command output to an external endpoint.
dist/tui.jsView on unpkg · L681A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/tui.jsView on unpkg · L681Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
postinstall.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/cli/skills/ast-grep/install.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
dist/cli/skills/ast-grep/tests/smoke.ps1View on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli-node/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli-node/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/matrixos.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/skills/superpowers-brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/lsp-daemon/dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/lsp-daemon/dist/client.jsView on unpkgPackage source references dynamic require/import behavior.
bin/oh-my-opencode.jsView on unpkg · L16Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/tui.jsView on unpkg · L681Source exposes local file and command tools to a remote model endpoint.
dist/tui.jsView on unpkg · L4518Package source references weak cryptographic algorithms.
dist/cli/skills/superpowers-brainstorming/scripts/server.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/skills/superpowers-brainstorming/scripts/server.cjsView on unpkg