Coding agent CLI with persistent memory, sub-agents, intelligent routing, and orchestration
LPM treats this as warn-only first-party agent extension lifecycle risk. The postinstall hook sets up Phi’s package-owned agent assets in the user’s Phi agent directory. This is an automatic agent extension setup, but the inspected behavior does not establish a confirmed attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references shell execution.
extensions/phi/providers/execution.tsView on unpkg · L84Package source references a known benign dynamic code generation pattern.
examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references dynamic require/import behavior.
dist/utils/photon.jsView on unpkg · L17Package source references weak cryptographic algorithms.
dist/core/tools/edit-hashline.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkgPackage ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/config.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/interactive-mode.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/tools-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/resolve-config-value.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/notify.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/git-merge-and-resolve.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/gondolin/index.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/export-html/vendor/highlight.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/export-html/vendor/marked.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/settings-selector.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/border-status-editor.tsView on unpkgThis report applies to @phi-code-admin/phi-code@0.99.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Package source references weak cryptographic algorithms.
dist/core/tools/edit-hashline.jsView on unpkg · L1Package ships WebAssembly modules.
examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
examples/extensions/doom-overlay/doom/build.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/config.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/interactive-mode.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/tools-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/resolve-config-value.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/notify.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/rpc/rpc-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/git-merge-and-resolve.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/gondolin/index.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/export-html/vendor/highlight.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/core/export-html/vendor/marked.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modes/interactive/components/settings-selector.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/border-status-editor.tsView on unpkgPackage source references shell execution.
extensions/phi/providers/execution.tsView on unpkg · L84Package source references a known benign dynamic code generation pattern.
examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references dynamic require/import behavior.
dist/utils/photon.jsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
examples/extensions/doom-overlay/doom/build/doom.jsView on unpkg