Snail Pi Web (蜗牛派) workspace for the pi coding agent
Installing the package modifies the installed pi-subagents dependency. At runtime, enabled web terminal and quick-command features can execute commands in allowed workspaces.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pi-web.jsView on unpkgPackage source references dynamic require/import behavior.
bin/pi-web.jsView on unpkg · L4Package source executes code through a VM context API.
lib/automation-extension-runtime.tsView on unpkg · L17Source reaches cloud instance metadata or link-local credential endpoints.
lib/automation-worker-runtime.cjsView on unpkg · L56Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
lib/automation-runner.tsView on unpkg · L18Package source invokes a package manager install command at runtime.
scripts/run-automation-smokes.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
scripts/start-pi-web-proxy.ps1View on unpkgPackage ships high-entropy non-source blobs.
.next/server/app/favicon.ico.bodyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.next/server/app/favicon.ico.bodyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/chatgpt-usage-refresh-scheduler.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/quick-command-runner.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-automation-run-now.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-bundled-pi-extensions-production.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-server-access-auth.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/run-desktop-pet.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/terminal-manager.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/automation-extension-discovery.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/npx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/pi-runtime-resolver.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/server-access-policy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/web-tools-config.tsView on unpkgThis report applies to @twofive/snail-pi-web@0.9.17.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pi-web.jsView on unpkgPackage source references dynamic require/import behavior.
bin/pi-web.jsView on unpkg · L4Package source executes code through a VM context API.
lib/automation-extension-runtime.tsView on unpkg · L17Source reaches cloud instance metadata or link-local credential endpoints.
lib/automation-worker-runtime.cjsView on unpkg · L56Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
lib/automation-runner.tsView on unpkg · L18Package source invokes a package manager install command at runtime.
scripts/run-automation-smokes.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
scripts/start-pi-web-proxy.ps1View on unpkgPackage ships high-entropy non-source blobs.
.next/server/app/favicon.ico.bodyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.next/server/app/favicon.ico.bodyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/chatgpt-usage-refresh-scheduler.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/quick-command-runner.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-automation-run-now.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-bundled-pi-extensions-production.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/e2e-server-access-auth.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/run-desktop-pet.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/terminal-manager.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/automation-extension-discovery.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/npx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/pi-runtime-resolver.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/server-access-policy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/web-tools-config.tsView on unpkg