Lightweight multi-agent TUI and stable cross-provider collaboration layer for Codex, Claude, Gemini, Grok, Kimi, and other CLI agents.
Inspectable source is a first-party npm wrapper that fetches the matching GitHub release, verifies SHA256SUMS, and bootstraps a managed runtime inside the package tree. No credential theft, foreign agent-config writes, or unrelated network sink is present in the published JavaScript.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkgThis report applies to @seemseam/ccb@8.6.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L54Package source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkg