VAIBot AI agent governance for Codex CLI — intercepts tool calls, classifies risk, enforces policy, and creates tamper-evident audit receipts with on-chain provenance anchoring.
LPM flags this version as an AI-agent control-surface risk. Installation automatically changes the user's global Codex configuration. It enables hooks and registers a remote VAIBot MCP service.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
vendor/vaibot-guard/scripts/vaibot-guard.mjs#virtual:normalized:round1View on unpkg · L10Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/pre-tool-use.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard-exec.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/lib/guard-launch.mjsView on unpkgThis report applies to @vaibot/codex-circuitbreaker-plugin@1.3.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L39Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L39A single source file combines environment access, network access, and code or shell execution with blocking evidence.
vendor/vaibot-guard/scripts/vaibot-guard.mjs#virtual:normalized:round1View on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
scripts/pre-tool-use.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard-exec.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/lib/guard-launch.mjsView on unpkgPackage source references child process execution.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
vendor/vaibot-guard/scripts/vaibot-guard.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L4