Hum: a self-improving coding agent for your terminal.
Installing the npm package runs an unpinned remote bootstrap script and then installs a separate Python package automatically. This executes third-party code before the user invokes the CLI.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L17Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L485A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L88734This report applies to @metaphi-ai/hum@0.2.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L4648Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L485A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L88734Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L17Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L4648