A Claude Code-style terminal app for running coding agents with worktree-isolated runs.
An explicit `rudder cloud <task>` creates a snapshot containing broad local credential material and uploads it to the package's cloud control plane. The collection is automatic for that command and is not limited to the project repository.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/improve/schedule.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/improve/schedule.jsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cloud.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cloud.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.mjsView on unpkg · L5Package ships native binary artifacts.
dist/native/darwin-arm64/rudder-nativeView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/improve/collect.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backends.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/task-summary.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/feedback.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cloud.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cloud.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cloud.jsView on unpkgPackage ships native binary artifacts.
dist/native/darwin-arm64/rudder-nativeView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/improve/collect.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backends.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/task-summary.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/feedback.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/improve/schedule.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/improve/schedule.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cloud.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.mjsView on unpkg · L5