Loading npm security reports…
🤖 开源安全的命令行 AI 编程助手,支持本地部署和国产模型
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references child process execution.
dist/tools/index.jsView on unpkg · L3Package source references weak cryptographic algorithms.
dist/local-embedder.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/updater.jsView on unpkg · L55Package source references child process execution.
dist/tools/index.jsView on unpkg · L3Package source references weak cryptographic algorithms.
dist/local-embedder.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/updater.jsView on unpkg · L55