Xyne CLI - A powerful AI assistant in your terminal with file operations, bash mode, drag-and-drop support, and multi-provider AI integration
LPM flags this version as an AI-agent control-surface risk. An automatic install hook modifies files belonging to a separate AI coding-agent dependency. No network endpoint is required for this control-surface mutation.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references child process execution.
dist-lib/src/pets/hosts/macos/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist-lib/src/agent/runtime/testing/llm-request-capture.jsView on unpkg · L21Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/jimp/dist/browser/index.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L40Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage ships native binary artifacts.
node_modules/@opentui/core-darwin-arm64/libopentui.dylibView on unpkgPackage ships WebAssembly modules.
node_modules/@opentui/core/assets/zig/tree-sitter-zig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/exif-parser/MakefileView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/src/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/src/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-lib/src/agent/tools/goal/extension.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-lib/src/utils/local-server.jsView on unpkgThis report applies to @xyne/xyne-cli@0.4.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L102Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L102Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L148Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L148Package source references child process execution.
dist-lib/src/pets/hosts/macos/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/jimp/dist/browser/index.jsView on unpkg · L1Package ships native binary artifacts.
node_modules/@opentui/core-darwin-arm64/libopentui.dylibView on unpkgPackage ships WebAssembly modules.
node_modules/@opentui/core/assets/zig/tree-sitter-zig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/exif-parser/MakefileView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/src/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/src/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-lib/src/agent/tools/goal/extension.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-lib/src/utils/local-server.jsView on unpkgPackage source references dynamic require/import behavior.
dist-lib/src/agent/runtime/testing/llm-request-capture.jsView on unpkg · L21Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L40Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkg