Cross-platform CLI for installing and running the Vibelet daemon
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references child process execution.
dist/web/assets/cobol-nwyudZeR.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/vibelet.mjsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/vibelet.mjsView on unpkg · L105Source writes installer persistence such as shell profile or service configuration.
dist/vibelet.mjsView on unpkg · L105Package source references a known benign dynamic code generation pattern.
dist/vibelet.mjsView on unpkg · L11101Package source references dynamic require/import behavior.
dist/web/assets/codeql-DsOJ9woJ.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.cjsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.cjsView on unpkg · L1Package source references child process execution.
dist/web/assets/cobol-nwyudZeR.jsView on unpkg · L1Package source references dynamic require/import behavior.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.cjsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.cjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/vibelet.mjsView on unpkg · L105Source writes installer persistence such as shell profile or service configuration.
dist/vibelet.mjsView on unpkg · L105Package source references a known benign dynamic code generation pattern.
dist/vibelet.mjsView on unpkg · L11101Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/vibelet.mjsView on unpkg