The mAI agent, directly in your terminal!
LPM flags this version as an AI-agent control-surface risk. Installation automatically invokes a separate Chrome MCP bridge registration flow. It also fetches and installs a remote executable into the package directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunks/protocolHandler-DPRTysDg.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/chunks/prompt-DPZFWvZz.jsView on unpkg · L149Package source references weak cryptographic algorithms.
dist/chunks/dist-es-fjXft-jH.jsView on unpkg · L1Package source matches protestware-related patterns.
dist/chunks/sentry-BEp-gDrC.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/sentry-BEp-gDrC.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L23Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L23Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/dist-es-DuAZyxJ02.jsView on unpkg · L3Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/src-B4RZ3Bik.jsView on unpkg · L19Package ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/chunks/loadAgentsDir-DbE28Kw5.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/ValidationErrorsList-DEKZebgA.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/createSSHSession-cz2LbC-m.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/dist-Cg1a1Exw.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/executor-0LskEQWE.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/open-CDditBQ-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cliLaunch-BQLM_VtG.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L65Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L65Package source references child process execution.
dist/chunks/protocolHandler-DPRTysDg.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/chunks/prompt-DPZFWvZz.jsView on unpkg · L149Package source references weak cryptographic algorithms.
dist/chunks/dist-es-fjXft-jH.jsView on unpkg · L1Package source matches protestware-related patterns.
dist/chunks/sentry-BEp-gDrC.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/sentry-BEp-gDrC.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L23Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L23Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/dist-es-DuAZyxJ02.jsView on unpkg · L3Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/src-B4RZ3Bik.jsView on unpkg · L19Package ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/chunks/loadAgentsDir-DbE28Kw5.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/ValidationErrorsList-DEKZebgA.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/createSSHSession-cz2LbC-m.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/dist-Cg1a1Exw.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/executor-0LskEQWE.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/open-CDditBQ-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cliLaunch-BQLM_VtG.jsView on unpkg