Waterbrother: bring-your-own-model coding CLI with local tools, sessions, operator modes, and approval controls
Speak mode sends the active model-provider API key and response text to a fixed xAI TTS endpoint. The active key can belong to OpenAI or Anthropic rather than xAI.
Package source references weak cryptographic algorithms.
src/codebase-index.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/listen-agent.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
src/listen-agent.jsView on unpkg · L3Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/cli.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tsnet-join.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/terminal-shell-hooks.zshView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/acp-proxy.js#virtual:string-array:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/voice.jsView on unpkgThis report applies to @tritard/waterbrother@0.17.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/cli.jsView on unpkgPackage source references weak cryptographic algorithms.
src/codebase-index.jsView on unpkg · L3Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/cli.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/terminal-shell-hooks.zshView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/acp-proxy.js#virtual:string-array:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/voice.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
src/listen-agent.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
src/listen-agent.jsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tsnet-join.jsView on unpkg · L1