Windows Code Relax LAN Bridge and CLI
LPM flags this version as an AI-agent control-surface risk. Global installation automatically changes the user-wide Codex app-server connection setting. This affects a foreign agent control surface beyond the package's own extension directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
tools/postinstall.mjsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/src/server.mjsView on unpkg · L2Package source executes code through a VM context API.
dist/src/server.mjsView on unpkg · L2Package source references weak cryptographic algorithms.
node_modules/ws/lib/websocket-server.jsView on unpkg · L5A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/platform/windows/desktop-host.mjsView on unpkg · L8Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/bin/codex-remote.mjsView on unpkg · L58Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/skill-install.mjsView on unpkgPackage ships native binary artifacts.
node_modules/@img/sharp-win32-x64/lib/sharp-win32-x64-0.35.4.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/tools/rtc-route-helper.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/web/vendor/markdown-it.umd.min.jsView on unpkgThis report applies to @walkhi/code-relax@0.1.0-beta.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L7Package source references child process execution.
tools/postinstall.mjsView on unpkg · L1Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/src/skill-install.mjsView on unpkgPackage ships native binary artifacts.
node_modules/@img/sharp-win32-x64/lib/sharp-win32-x64-0.35.4.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
dist/tools/rtc-route-helper.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/web/vendor/markdown-it.umd.min.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/src/server.mjsView on unpkg · L2Package source executes code through a VM context API.
dist/src/server.mjsView on unpkg · L2Package source references weak cryptographic algorithms.
node_modules/ws/lib/websocket-server.jsView on unpkg · L5A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/platform/windows/desktop-host.mjsView on unpkg · L8Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/bin/codex-remote.mjsView on unpkg · L58