registry  /  @letta-ai/letta-code  /  0.27.22

@letta-ai/letta-code@0.27.22

⚠ Under review

Letta Code is a CLI tool for interacting with stateful Letta agents from the terminal.

Static Scan Results

scanned 6h ago · by rust-scanner

Static analysis flagged 15 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.; previous stored version diff introduced dangerous source

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoEnvironmentVarsFilesystemNetworkShellWebSocket
Supply chain
HighEntropyStringsObfuscatedUrlStrings
ManifestNo manifest risk signals triggered.
scanned 41 file(s), 686 KB of source, external domains: api.github.com, api.letta.com, app.letta.com, docs.expo.dev, github.com
Oversized source lightweight scan
letta.js32.6 MB file, sampled 256 KB
FilesystemChildProcessEnvironmentVarsCryptoHighEntropyStringsUrlStringsapi.letta.comapp.letta.comdocs.expo.dev

Source & flagged code

6 flagged · loading source
package.jsonView file
scripts.postinstall = node scripts/postinstall-patches.js || echo letta: vendor patches skipped && node -e "try{require('fs').chmodSync(require('path').join(require.resolve('node-pty/package.json'),'../...
Critical
Red Install Lifecycle Script

Install-time lifecycle script matches a deterministic static-gate block pattern.

package.jsonView on unpkg
scripts.postinstall = node scripts/postinstall-patches.js || echo letta: vendor patches skipped && node -e "try{require('fs').chmodSync(require('path').join(require.resolve('node-pty/package.json'),'../...
High
Install Time Lifecycle Scripts

Package defines install-time lifecycle scripts.

package.jsonView on unpkg
skills/initializing-memory/scripts/list-sessions.shView file
path = skills/initializing-memory/scripts/list-sessions.sh kind = build_helper sizeBytes = 3510 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

skills/initializing-memory/scripts/list-sessions.shView on unpkg
letta.jsView file
path = letta.js kind = oversized_source_file sizeBytes = 34235246 magicHex = [redacted]
High
Oversized Source File

Package contains source files above the static scanner size ceiling.

letta.jsView on unpkg
path = letta.js kind = oversized_cli_entrypoint sizeBytes = 34235246 magicHex = [redacted]
Medium
Oversized Cli Entrypoint

Package contains an oversized executable-looking CLI entrypoint.

letta.jsView on unpkg
scripts/codex-watch/release-analysis.tsView file
matchType = previous_version_dangerous_delta matchedPackage = @letta-ai/letta-code@0.27.19 matchedIdentity = npm:QGxldHRhLWFpL2xldHRhLWNvZGU:0.27.19 similarity = 0.971 summary = stored previous version shares package body but lacks this dangerous source file
Critical
Previous Version Dangerous Delta

This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.

scripts/codex-watch/release-analysis.tsView on unpkg

Findings

2 Critical2 High5 Medium6 Low
CriticalRed Install Lifecycle Scriptpackage.json
CriticalPrevious Version Dangerous Deltascripts/codex-watch/release-analysis.ts
HighInstall Time Lifecycle Scriptspackage.json
HighOversized Source Fileletta.js
MediumNetwork
MediumEnvironment Vars
MediumShips Build Helperskills/initializing-memory/scripts/list-sessions.sh
MediumOversized Cli Entrypointletta.js
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowObfuscated
LowHigh Entropy Strings
LowUrl Strings