No confirmed malicious attack surface. Runtime commands manage UiPath LLM Gateway BYO connections and use UiPath authentication plus telemetry.
Static reason
One or more suspicious static signals were detected.
Trigger
User imports the plugin and invokes registered llm-configuration byo-connections commands.
Impact
Expected CLI API operations against the user's UiPath tenant; no unrelated exfiltration or install-time behavior confirmed.
Mechanism
Authenticated UiPath API client with token refresh and local auth-file update
Rationale
The suspicious primitives are aligned with a UiPath CLI plugin: authenticated API requests, token refresh, local auth storage, robot IPC fallback, and telemetry. Static inspection found no lifecycle execution, hidden payload, unrelated endpoint, credential exfiltration, or AI-agent control-surface mutation.
Evidence
package.jsondist/tool.js~/.uipath/.auth
Network endpoints6
cloud.uipath.com<authority>/identity_/connect/token<authority>/<org>/<tenant>/llmgateway_/api/byo/product/llm-configurations<authority>/<org>/<tenant>/llmgateway_/api/byom/productswesteurope-5.in.applicationinsights.azure.com//