syCode — terminal coding agent + team daemon sidecar for remote monitoring.
No install-time execution or unconsented control-surface mutation is present. Runtime cloud synchronization and installer execution are tied to logged-in use and an explicit update command.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/src/cloud.jsView on unpkgPackage source references child process execution.
dist/src/cloud.jsView on unpkg · L167Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Package source references dynamic require/import behavior.
dist/extensions/sycode-ui/index.jsView on unpkg · L4302Source downloads or fetches remote code and executes it.
dist/src/cli.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4This report applies to @synotech/code@0.1.10.
See version security history for other recorded verdicts.
Evidence last updated: .
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/src/cloud.jsView on unpkgSource downloads or fetches remote code and executes it.
Package source references child process execution.
dist/src/cloud.jsView on unpkg · L167Package source references dynamic require/import behavior.
dist/extensions/sycode-ui/index.jsView on unpkg · L4302A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4