AdoreMix broadcast server - cross-platform installer, runner and service manager
An explicitly installed configuration-manager service exposes an unauthenticated network API on port 9877. It can disclose API keys from and rewrite the root OpenClaw configuration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references child process execution.
tts/providers/edge.jsView on unpkg · L11Package source references a known benign dynamic code generation pattern.
webui/high/assets/index-npdYRXyk.jsView on unpkg · L17Package source references dynamic require/import behavior.
bin/postinstall-hint.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
src/config-manager.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/config-manager.jsView on unpkg · L4This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/tts-deps.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/tts-deps.jsView on unpkg · L294Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/doctor.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
src/install.jsView on unpkg · L105Package ships non-JavaScript build or shell helper files.
config-manager/app.pyView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
webui/high/assets/index-npdYRXyk.jsView on unpkg · L17Package source references dynamic require/import behavior.
bin/postinstall-hint.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
src/install.jsView on unpkg · L105Package ships non-JavaScript build or shell helper files.
config-manager/app.pyView on unpkgPackage source references child process execution.
tts/providers/edge.jsView on unpkg · L11Source writes installer persistence such as shell profile or service configuration.
src/config-manager.jsView on unpkg · L4A manifest entrypoint or package-local install chain reaches persistence behavior.
src/config-manager.jsView on unpkg · L4A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/tts-deps.jsView on unpkg · L294This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/tts-deps.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.