registry  /  @linzumi/cli  /  1.0.16

@linzumi/cli@1.0.16

⚠ Under review

Linzumi CLI — point a Codex agent at the real code on your laptop, with your team watching and steering from shared threads.

Static Scan Results

scanned 2d ago · by rust-scanner

Static analysis flagged 18 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessDynamicRequireEnvironmentVarsFilesystemNetworkShellWebSocket
Supply chain
HighEntropyStringsMinifiedObfuscatedUrlStrings
ManifestNo manifest risk signals triggered.
scanned 12 file(s), 2.17 MB of source, external domains: 0.0.0.0, 127.0.0.1, api.groq.com, app.linzumi.com, brew.sh, fonts.googleapis.com, fonts.gstatic.com, github.com, json-schema.org, linzumi.com, nodejs.org, openrouter.ai, registry.npmjs.org, serve.linzumi.com, www.w3.org

Source & flagged code

8 flagged · loading source
dist/index.jsView file
19if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... ... L30: `," ")}function Dl(e){if(!ie(e))return;let n=q(e.payload)??{},t=q(e.actor),r=ue(e.seq),o=m(e.type);if(!(r===void 0||o===void 0))return{seq:r,type:o,actorKind:m(t?.kind),actorSlug:m... L31: `)}function jS(e){return e.flatMap(n=>n.isImage?[{type:"localImage",path:n.path}]:[])}async function yg(e,n){let t=await hg(e,n),r=gg(n.body,t,{uploadInstructionMode:"footer"}),o=t... L32: `)}function QF(e,n){let t=ZF(e);switch(t.trim()===""&&n.length>0){case!0:return"Attached file.";case!1:return t}}function XF(e,n){return m(e.kind)==="codex_assistant_message"?{...e...
Critical
Same File Env Network Execution

A single source file combines environment access, network access, and code or shell execution with blocking evidence.

dist/index.jsView on unpkg · L19
2const require = createRequire(import.meta.url); L3: var gL=Object.create;var Qh=Object.defineProperty;var yL=Object.getOwnPropertyDescriptor;var xL=Object.getOwnPropertyNames;var vL=Object.getPrototypeOf,bL=Object.prototype.hasOwnPr... L4: const { workerData, parentPort } = require('node:worker_threads'); ... L19: if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... L22: `).map(o=>o.trim()).find(o=>o.startsWith("# "))?.replace(/^#+\s+/u,"").trim();return r===void 0||r===""?void 0:r}catch{return}}function oF(e){return Object.fromEntries(Object.entri... L23: `).filter(n=>n.trim()!=="").flatMap(n=>{try{let t=JSON.parse(n);return ie(t)?[t]:[]}catch{return[]}})}catch{return[]}}function yF(e){return e.flatMap((n,t)=>{if(n.type!=="response_... ... L27: ${u}`.split(` L28: `).filter(c=>c.trim()!=="")}catch{return[]}final
Critical
Remote Asset Decode Execute

Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.

dist/index.jsView on unpkg · L2
19Trigger-reachable chain: manifest.bin -> bin/linzumi.js -> dist/index.js L19: if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... ... L30: `," ")}function Dl(e){if(!ie(e))return;let n=q(e.payload)??{},t=q(e.actor),r=ue(e.seq),o=m(e.type);if(!(r===void 0||o===void 0))return{seq:r,type:o,actorKind:m(t?.kind),actorSlug:m... L31: `)}function jS(e){return e.flatMap(n=>n.isImage?[{type:"localImage",path:n.path}]:[])}async function yg(e,n){let t=await hg(e,n),r=gg(n.body,t,{uploadInstructionMode:"footer"}),o=t... L32: `)}function QF(e,n){let t=ZF(e);switch(t.trim()===""&&n.length>0){case!0:return"Attached file.";case!1:return t}}function XF(e,n){return m(e.kind)==="codex_assistant_message"?{...e...
Critical
Trigger Reachable Dangerous Capability

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

dist/index.jsView on unpkg · L19
19if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(...
High
Child Process

Package source references child process execution.

dist/index.jsView on unpkg · L19
19if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... ... L30: `," ")}function Dl(e){if(!ie(e))return;let n=q(e.payload)??{},t=q(e.actor),r=ue(e.seq),o=m(e.type);if(!(r===void 0||o===void 0))return{seq:r,type:o,actorKind:m(t?.kind),actorSlug:m... L31: `)}function jS(e){return e.flatMap(n=>n.isImage?[{type:"localImage",path:n.path}]:[])}async function yg(e,n){let t=await hg(e,n),r=gg(n.body,t,{uploadInstructionMode:"footer"}),o=t... L32: `)}function QF(e,n){let t=ZF(e);switch(t.trim()===""&&n.length>0){case!0:return"Attached file.";case!1:return t}}function XF(e,n){return m(e.kind)==="codex_assistant_message"?{...e...
High
Command Output Exfiltration

Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.

dist/index.jsView on unpkg · L19
2const require = createRequire(import.meta.url); L3: var gL=Object.create;var Qh=Object.defineProperty;var yL=Object.getOwnPropertyDescriptor;var xL=Object.getOwnPropertyNames;var vL=Object.getPrototypeOf,bL=Object.prototype.hasOwnPr... L4: const { workerData, parentPort } = require('node:worker_threads'); ... L19: if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... L22: `).map(o=>o.trim()).find(o=>o.startsWith("# "))?.replace(/^#+\s+/u,"").trim();return r===void 0||r===""?void 0:r}catch{return}}function oF(e){return Object.fromEntries(Object.entri... L23: `).filter(n=>n.trim()!=="").flatMap(n=>{try{let t=JSON.parse(n);return ie(t)?[t]:[]}catch{return[]}})}catch{return[]}}function yF(e){return e.flatMap((n,t)=>{if(n.type!=="response_... ... L27: ${u}`.split(` L28: `).filter(c=>c.trim()!=="")}catch{return[]}final
High
Sandbox Evasion Gated Capability

Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.

dist/index.jsView on unpkg · L2
2Cross-file remote execution chain: dist/index.js spawns dist/mcp-server.mjs; helper contains network access plus dynamic code execution. L2: const require = createRequire(import.meta.url); L3: var gL=Object.create;var Qh=Object.defineProperty;var yL=Object.getOwnPropertyDescriptor;var xL=Object.getOwnPropertyNames;var vL=Object.getPrototypeOf,bL=Object.prototype.hasOwnPr... L4: const { workerData, parentPort } = require('node:worker_threads'); ... L19: if (parentPort) parentPort.postMessage(result); L20: `});var eS={};Es(eS,{discoverCurrentGitProject:()=>qL});import{spawnSync as AL}from"node:child_process";import{homedir as ML}from"node:os";import{existsSync as H_,readdirSync as G_... L21: `).flatMap(t=>t.startsWith("worktree ")?[t.slice(9)]:[])}function rF(e){let n=["README.md","README.markdown","readme.md"].map(t=>Ds(e,t)).find(t=>H_(t));if(n!==void 0)try{let r=OL(... L22: `).map(o=>o.trim()).find(o=>o.startsWith("# "))?.replace(/^#+\s+/u,"").trim();return r===void 0||r===""?void 0:r}catch{return}}function oF(e){return Object.fromEntries(Object.entri... L23: `).filter(n=>n.trim()!=="").flatMap(n=>{try{let t=JSON.parse(n);return ie(t)?[t]:[]}catch{return[]}})}catch{return[]}}func…
High
Cross File Remote Execution Context

Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.

dist/index.jsView on unpkg · L2
scripts/qa/codex-keychain-partition-repro.shView file
path = scripts/qa/codex-keychain-partition-repro.sh kind = build_helper sizeBytes = 5989 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

scripts/qa/codex-keychain-partition-repro.shView on unpkg

Findings

3 Critical5 High5 Medium5 Low
CriticalSame File Env Network Executiondist/index.js
CriticalRemote Asset Decode Executedist/index.js
CriticalTrigger Reachable Dangerous Capabilitydist/index.js
HighChild Processdist/index.js
HighShell
HighCommand Output Exfiltrationdist/index.js
HighSandbox Evasion Gated Capabilitydist/index.js
HighCross File Remote Execution Contextdist/index.js
MediumDynamic Require
MediumNetwork
MediumEnvironment Vars
MediumShips Build Helperscripts/qa/codex-keychain-partition-repro.sh
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowObfuscated
LowHigh Entropy Strings
LowUrl Strings