OpenCode plugin for Paytaca AI - AI inference provider powered by Bitcoin Cash micropayments
LPM treats this as warn-only first-party agent extension lifecycle risk. When OpenCode loads the plugin, it modifies OpenCode-related configuration, creates a wallet if absent, and starts a detached local payment proxy. A later chat response confirming a 402 payment can cause BCH to be sent through paytaca-cli.
Package source references dynamic require/import behavior.
bin/paytaca.jsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bundled/proxy.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundled/proxy.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/proxy.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/proxy.jsView on unpkgPackage source references dynamic require/import behavior.
bin/paytaca.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/proxy.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundled/proxy.jsView on unpkg · L16Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bundled/proxy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/proxy.jsView on unpkg